Skip to main content
Glama

add_iam_policy_binding

Grant IAM roles to specific users or service accounts in a GCP project by adding policy bindings. Specify project ID, role, and member to assign access permissions securely.

Instructions

    Add an IAM policy binding to a GCP project.
    
    Args:
        project_id: The ID of the GCP project
        role: The role to grant (e.g., "roles/compute.admin")
        member: The member to grant the role to (e.g., "user:email@example.com", "serviceAccount:name@project.iam.gserviceaccount.com")
    
    Returns:
        Result of the policy binding operation
    

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
memberYes
project_idYes
roleYes

Implementation Reference

  • The handler function that implements the 'add_iam_policy_binding' tool logic. It uses Google Cloud APIs to modify the IAM policy of a project by adding a new binding for a member to a specific role, with checks to avoid duplicates.
        def add_iam_policy_binding(project_id: str, role: str, member: str) -> str:
            """
            Add an IAM policy binding to a GCP project.
            
            Args:
                project_id: The ID of the GCP project
                role: The role to grant (e.g., "roles/compute.admin")
                member: The member to grant the role to (e.g., "user:email@example.com", "serviceAccount:name@project.iam.gserviceaccount.com")
            
            Returns:
                Result of the policy binding operation
            """
            try:
                from google.cloud import resourcemanager_v3
                from google.iam.v1 import iam_policy_pb2, policy_pb2
                
                # Initialize the Resource Manager client
                client = resourcemanager_v3.ProjectsClient()
                
                # Get the current IAM policy
                get_request = iam_policy_pb2.GetIamPolicyRequest(
                    resource=f"projects/{project_id}"
                )
                policy = client.get_iam_policy(request=get_request)
                
                # Check if the binding already exists
                binding_exists = False
                for binding in policy.bindings:
                    if binding.role == role and member in binding.members:
                        binding_exists = True
                        break
                
                if binding_exists:
                    return f"IAM policy binding already exists: {member} already has role {role} in project {project_id}."
                
                # Add the new binding
                binding = policy_pb2.Binding()
                binding.role = role
                binding.members.append(member)
                policy.bindings.append(binding)
                
                # Set the updated IAM policy
                set_request = iam_policy_pb2.SetIamPolicyRequest(
                    resource=f"projects/{project_id}",
                    policy=policy
                )
                updated_policy = client.set_iam_policy(request=set_request)
                
                return f"""
    IAM policy binding added successfully:
    - Project: {project_id}
    - Role: {role}
    - Member: {member}
    """
            except Exception as e:
                return f"Error adding IAM policy binding: {str(e)}"
  • Type hints and docstring provide the input schema (project_id, role, member) and output description for the MCP tool.
    def add_iam_policy_binding(project_id: str, role: str, member: str) -> str:
        """
        Add an IAM policy binding to a GCP project.
        
        Args:
            project_id: The ID of the GCP project
            role: The role to grant (e.g., "roles/compute.admin")
            member: The member to grant the role to (e.g., "user:email@example.com", "serviceAccount:name@project.iam.gserviceaccount.com")
        
        Returns:
            Result of the policy binding operation
        """
  • The @mcp.tool() decorator on the handler function registers it as an MCP tool named 'add_iam_policy_binding' (derived from function name).
    @mcp.tool()
  • Within the module registration function, calls register_tools from iam_tools module, which defines and registers the 'add_iam_policy_binding' tool.
    iam_tools.register_tools(mcp)
  • Imports the IAM tools module containing the register_tools function and the add_iam_policy_binding tool implementation.
    from .gcp_modules.iam import tools as iam_tools

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.0.0

TDQS

B3.2/5.0
Behavior1/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations are absent, so the description carries the full burden of behavioral disclosure. It does not mention side effects, required permissions, idempotency, or any operational nuances beyond the basic action. This is a significant gap for a mutation tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description follows a clear, organized docstring format with a one-line summary, Args section, and Returns. It is concise and front-loaded, though the Returns line is vague and could be more specific.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a mutation tool with no annotations or output schema, the description lacks essential context such as permission requirements, potential side effects, or what the result precisely contains. It is minimally adequate but leaves gaps for an agent to use it safely.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, but the description compensates fully by explaining each parameter with concrete examples (e.g., role, member, project_id). This adds critical meaning that the bare schema lacks.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function with a specific verb and resource: 'Add an IAM policy binding to a GCP project.' This distinguishes it from sibling tools like check_iam_permissions and list_roles, which serve different purposes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool vs alternatives. It does not mention any prerequisites, context, or sibling tools, leaving the agent without decision-making information.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.