ADO Guard MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ADO_PAT | Yes | Azure DevOps Personal Access Token. Give it the narrowest scopes you need (required) | |
| ADO_ORG_URL | Yes | Azure DevOps organization URL, e.g. https://dev.azure.com/your-org (required) | |
| ADO_GUARD_MOCK | No | Use the built-in fictional org instead of a real one | false |
| ADO_GUARD_MODE | No | Either read-only or read-write | read-only |
| ADO_GUARD_POLICY | No | Path to a JSON policy file | |
| ADO_GUARD_DRY_RUN | No | Preview writes without executing | false |
| ADO_GUARD_PROJECTS | No | Comma-separated project allowlist | all |
| ADO_GUARD_AUDIT_FILE | No | Append audit entries as JSON lines | in-memory |
| ADO_GUARD_ALLOW_DESTRUCTIVE | No | Enable delete_work_item and run_pipeline | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_projectsB | List Azure DevOps projects the server is allowed to access. |
| search_work_itemsA | Find work items in a project by type, state, assignee or text in the title. Returns compact summaries; use get_work_item for full detail. |
| get_work_itemB | Get full details of one work item, including description and tags. |
| list_pull_requestsC | List pull requests in a project, optionally for one repository. |
| get_pull_requestB | Get one pull request with reviewers, linked work items and changed files. |
| list_pipelinesC | List pipelines defined in a project. |
| list_pipeline_runsB | List recent runs of a pipeline with their state and result. |
| guard_get_policyA | Show the active guardrail policy so you can explain to the user what you're allowed to do. |
| guard_get_audit_logB | Show the most recent tool calls and whether they were allowed, denied or awaiting approval. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 9 tools
Each tool targets a distinct resource and action: list vs. get pairs (work items, PRs) are clearly differentiated, and search_work_items vs. get_work_item are explicitly distinguished in the descriptions. The two guard_ tools (audit log, policy) are also unambiguous.
All tools follow a consistent snake_case verb_noun pattern (list_projects, get_work_item, search_work_items, list_pipeline_runs). The guard_ prefix on two tools acts as a clear namespace rather than an inconsistency.
Nine tools is well-scoped for a guarded read surface over Azure DevOps. Each tool earns its place with no redundant or filler operations.
The read surface covers projects, work items, PRs and pipelines reasonably, but there are notable gaps: no repository listing, no single-pipeline or single-run detail, and no write operations (create/update/comment) anywhere. Some of this may be intentional for a guardrail server, but agents will hit dead ends for common detail and mutation workflows.