Skip to main content
Glama

v2_audit_logs

Read-onlyIdempotent

Fetch audit log entries to see who changed what, from which IP, with old and new values, providing an accountability trail.

Instructions

AUDIT log: who changed what, from which IP, with old and new values. This is the accountability trail — separate from events.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
hoursNo
limitNo
siteIdNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv4.0.0

TDQS

A3.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false and closed-world, so the safety profile is covered. The description adds what fields are returned (actor, IP, old/new values), which is useful content context, but it says nothing about pagination, time defaults, rate limits, or volume caps.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences, front-loaded with the core content and ending with the sibling distinction. No filler or repetition.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema and zero parameter description coverage, the definition should at least explain what hours/limit/siteId control. It only explains the return content conceptually, leaving the agent unable to call the tool correctly with non-default arguments.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters1/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% for three parameters (hours, limit, siteId), so the description carries the full burden of explaining them and explains none. There is no hint about what hours window, limit bound, or siteId scoping do or what their defaults are.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States the resource (AUDIT log) and its content precisely: who changed what, source IP, and old/new values. It also explicitly distinguishes itself from the closest sibling, v2_events ('separate from events'), so an agent can route without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description names an alternative (v2_events) and asserts this is a different kind of trail, which gives a clear selection rule. It stops short of a full when-to-use statement (e.g., no guidance on when to prefer v2_security_audit or v2_radar_audit), so it lands just below the top band.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.