Skip to main content
Glama
josimarh

azure-mcp-pilot

by josimarh

get_identity_access_summary

Read-onlyIdempotent

Summarizes Microsoft Entra ID and Azure RBAC identities, showing total, enabled/disabled users, direct permissions, and disabled accounts with active roles.

Instructions

Retorna resumo de identidade e RBAC:

  • total de usuários

  • usuários habilitados/desabilitados

  • usuários com permissões diretas

  • usuários desabilitados com roles ativas

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint, so the safety profile is fully covered externally. The description adds the content breakdown, which is useful, but says nothing about cost, caching/freshness of the aggregated counts, or the shape of the response. With annotations carrying the behavioral load, a 3 is appropriate.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A one-line purpose statement followed by four terse bullets; the content is front-loaded and each bullet names a distinct returned metric, so nothing is wasted. Slightly over-fragmented for the amount of information, but efficient.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With zero parameters and no output schema, the description carries the burden of describing the return value — and it does, by enumerating the four aggregate metrics, which is exactly what an agent needs to decide to call it. What is missing is any indication of scope or freshness of the counts.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so the schema baseline for this dimension is 4. There is nothing for the description to clarify beyond what the empty argument object already communicates.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Retorna resumo de identidade e RBAC') and enumerates the four metrics returned (total users, enabled/disabled, direct permissions, disabled with active roles). It is clearly an aggregate-overview tool rather than a listing tool. However, it never names a sibling to differentiate itself from list_users or list_disabled_users_with_active_roles.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no explicit when-to-use or when-not-to-use guidance and no alternatives named, despite heavy sibling overlap (list_users, list_users_with_direct_permissions, list_disabled_users_with_active_roles). Usage is only implied by the enumerated contents: an agent can infer this is a quick overview rather than a detailed listing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools