Skip to main content
Glama

Deadlines for an incident

najjab_deadlines
Read-onlyIdempotent

Compute Gulf cyber incident notification deadlines by country, authority, and severity from discovery time, including follow-ups, closure reports, and severity-change notes.

Instructions

Every notification duty an incident triggers across the given countries, soonest first, with the due time computed from the discovery time, follow up updates and closure reports, and notes when the severity grade changes the answer.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
langNoLanguage for the answer: en or ar.en
zonesNoFinancial free zones the organization also operates in: difc and adgm (UAE), qfc (Qatar). Their data protection duties are added; federal duties still apply outside the zone.
sectorNogeneral, banking, insurance, payments, telecom, government or critical (critical infrastructure).general
severityNoThe grade your own classification gives: critical, high, medium or low.high
countriesYesEvery country the organization operates in, for example ["KW", "SA"].
discovered_atYesWhen the incident was discovered, ISO 8601 with offset, for example "2026-10-04T08:00:00+03:00".
incident_typeYesransomware, bec (business email compromise), data-breach or cloud-key (exposed cloud access keys).
personal_dataNoTrue when personal data was affected. A data-breach always counts as personal data.
response_formatNomarkdown for reading, json for further processing.markdown

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover safety (readOnly, idempotent, non-destructive, closed world). The description adds real behavioral context beyond them: results are ordered soonest first, due times are computed from the discovery time, follow-up updates and closure reports are included, and the answer changes with the severity grade. Return format/limits are not stated, so 4 not 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The core output is front-loaded ('Every notification duty an incident triggers across the given countries, soonest first') and each clause conveys distinct information. It is one dense run-on sentence, which slightly hurts readability but contains no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With 9 parameters, no output schema, and strong annotations, the description does the important work of describing the return shape (duties, ordering, computed dues, severity-conditioned notes). Remaining gaps, such as how zones or sector alter results and output formatting, are largely covered by the schema's parameter descriptions.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with rich enum descriptions, so the baseline is 3. The description adds interpretation beyond the schema by explaining that due times derive from discovered_at and that severity/grade conditionally alters the output, clarifying how parameters drive results.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the resource returned: every notification duty an incident triggers across given countries, with deadlines computed from discovery time. It is distinguishable from siblings like najjab_list_obligations or najjab_calendar because it is derived from an incident and computed rather than a static list. It stops short of naming a sibling it replaces, so it earns a 4 rather than a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by the scenario: an incident has occurred and you need its resulting deadlines. There is no explicit when-to-use/when-not, no prerequisites, and no routing to alternatives such as najjab_playbook or najjab_calendar, leaving the agent to infer the right moment to call it.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.