Skip to main content
Glama
ManoAlee

Enterprise Microsoft 365 MCP Server

by ManoAlee

compliance_audit_retention_policies

Audit Exchange Online retention policies and MRM tags for GDPR/LGPD compliance, revealing configuration gaps that need remediation.

Instructions

Audits retention policies and MRM tags configured in Exchange Online for compliance/GDPR/LGPD.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.0.0

TDQS

A3.7/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are supplied, so the description carries the full behavioral burden. The verb 'Audits' implies a non-destructive read, and an output schema exists to cover return values, but the description never explicitly confirms it is read-only, mentions permission/auth needs, or states its scope (tenant-wide vs per-mailbox).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with the verb first and zero filler. It is appropriately sized, though one more clause on scope would not have hurt.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a no-parameter audit whose return shape is defined by an output schema, the description covers what is inspected and under which compliance regimes. The only real gaps are the absence of annotations and any statement of scope or safety, which slightly weakens completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so the baseline of 4 applies. There is no parameter syntax the description could or should add.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ('Audits') plus a precise resource ('retention policies and MRM tags configured in Exchange Online') and a regulatory scope (compliance/GDPR/LGPD). This clearly distinguishes it from siblings like compliance_audit_litigation_hold or compliance_audit_recoverable_items, which audit different artifacts.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description names the compliance context but gives no when-to-use trigger, prerequisites, or comparison to the other compliance_audit_* tools. An agent must infer on its own when this audit is the right call versus litigation hold or recoverable items audits.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.