Skip to main content
Glama
zscaler

zscaler-mcp-server

Official
by zscaler

get_zia_user_groups

Read-only

Read ZIA user groups: fetch by ID, find by name, or list (read-only).

Instructions

Read ZIA user groups: fetch by ID, find by name, or list (read-only).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNo
pageNo
queryNoOptional JMESPath expression applied to the results after the API call, for client-side filtering and projection. Examples: "[?enabled==`true`]", "[*].{name: name, id: id}", "length(@)". Omit to get the full records. IMPORTANT: field names are the keys of the returned records, which are usually snake_case (`custom_category`) even where the Zscaler API documents camelCase (`customCategory`) — guessing the spelling yields an empty list that looks like a real answer. If you have not already seen a record from this tool, call it once without `query` and read the keys off the response.
searchNo
sort_byNo
group_idNo
page_sizeNo
defined_byNo
sort_orderNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed12 schema fields changedv0.15.3
    • removedInput schema / additionalProperties
      Removed value: -false
    • addedInput schema / properties / defined_by / title
      Added value: +"Defined By"
    • addedInput schema / properties / group_id / title
      Added value: +"Group Id"
    • addedInput schema / properties / name / title
      Added value: +"Name"
    • addedInput schema / properties / page / title
      Added value: +"Page"
    • addedInput schema / properties / page_size / title
      Added value: +"Page Size"
    • changedInput schema / properties / query / description
      Previous value: -"Optional JMESPath expression applied to the results after the API call, for client-side filtering and projection. Field names are exactly what the Zscaler API returns. Examples: \"[?enabled==`true`]\", \"[*].{name: name, id: id}\", \"length(@)\". Omit to get the full records."New value: +"Optional JMESPath expression applied to the results after the API call, for client-side filtering and projection. Examples: \"[?enabled==`true`]\", \"[*].{name: name, id: id}\", \"length(@)\". Omit to get the full records. IMPORTANT: field names are the keys of the returned records, which are usually snake_case (`custom_category`) even where the Zscaler API documents camelCase (`customCategory`) — guessing the spelling yields an empty list that looks like a real answer. If you have not already seen a record from this tool, call it once without `query` and read the keys off the response."
    • addedInput schema / properties / query / title
      Added value: +"Query"
    • addedInput schema / properties / search / title
      Added value: +"Search"
    • addedInput schema / properties / sort_by / title
      Added value: +"Sort By"
    • addedInput schema / properties / sort_order / title
      Added value: +"Sort Order"
    • addedInput schema / title
      Added value: +"get_zia_user_groupsArguments"
  2. Changed23 schema fields changedv0.14.0
    • addedInput schema / additionalProperties
      Added value: +false
    • removedInput schema / properties / action
      Removed value: -{
      -  "const": "read",
      -  "default": "read",
      -  "description": "Operation to perform. Use 'read' to paginate/filter groups or fetch a single group by ID.",
      -  "title": "Action",
      -  "type": "string"
      -}
    • removedInput schema / properties / defined_by / description
      Removed value: -"String value defined by the group name or other applicable attributes. Used to further filter results."
    • removedInput schema / properties / defined_by / title
      Removed value: -"Defined By"
    • changedInput schema / properties / group_id / anyOf
      Previous value: -[
      -  {
      -    "type": "integer"
      -  },
      -  {
      -    "type": "string"
      -  },
      -  {
      -    "type": "null"
      -  }
      -]New value: +[
      +  {
      +    "type": "string"
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
    • removedInput schema / properties / group_id / description
      Removed value: -"ID of the user group. When provided, returns a single group; otherwise returns a list of groups."
    • removedInput schema / properties / group_id / title
      Removed value: -"Group Id"
    • removedInput schema / properties / name / description
      Removed value: -"Case-insensitive substring match on the group's name field. Resolved client-side AFTER fetching the full group list, so names like 'A000', 'a000', 'HR', 'finance' all match regardless of the underlying name's casing. Use this when you have a literal group name from the admin and just need to find its ID. The server-side `search` parameter is unreliable for groups (it sometimes matches user login IDs instead of group names) — prefer `name` for find-by-name workflows."
    • removedInput schema / properties / name / title
      Removed value: -"Name"
    • removedInput schema / properties / page / description
      Removed value: -"Page offset for pagination when listing groups."
    • removedInput schema / properties / page / title
      Removed value: -"Page"
    • removedInput schema / properties / page_size / description
      Removed value: -"Page size for listing groups. Default is 100; maximum is 1000."
    • removedInput schema / properties / page_size / title
      Removed value: -"Page Size"
    • addedInput schema / properties / query
      Added value: +{
      +  "anyOf": [
      +    {
      +      "type": "string"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "Optional JMESPath expression applied to the results after the API call, for client-side filtering and projection. Field names are exactly what the Zscaler API returns. Examples: \"[?enabled==`true`]\", \"[*].{name: name, id: id}\", \"length(@)\". Omit to get the full records."
      +}
    • removedInput schema / properties / search / description
      Removed value: -"Server-side query forwarded to the ZIA list_groups endpoint. ZIA's documented behavior here is unreliable (the API has been observed to match against user login IDs rather than group names). Prefer `name` for case-insensitive substring matching on the group's name. Use `search` only when you specifically need the server-side semantics."
    • removedInput schema / properties / search / title
      Removed value: -"Search"
    • removedInput schema / properties / service
      Removed value: -{
      -  "default": "zia",
      -  "description": "Zscaler service name. Always 'zia' for this tool.",
      -  "title": "Service",
      -  "type": "string"
      -}
    • removedInput schema / properties / sort_by / description
      Removed value: -"Sort field for listing groups. Supported: id, name, expiry, status, external_id, rank, mod_time."
    • removedInput schema / properties / sort_by / title
      Removed value: -"Sort By"
    • removedInput schema / properties / sort_order / description
      Removed value: -"Sort order for listing groups. Supported: asc, desc, rule_execution."
    • removedInput schema / properties / sort_order / title
      Removed value: -"Sort Order"
    • removedInput schema / title
      Removed value: -"zia_user_group_managerArguments"
    • changedOutput schema / (root)
      Previous value: -{
      -  "properties": {
      -    "result": {
      -      "anyOf": [
      -        {
      -          "additionalProperties": true,
      -          "type": "object"
      -        },
      -        {
      -          "items": {
      -            "additionalProperties": true,
      -            "type": "object"
      -          },
      -          "type": "array"
      -        }
      -      ],
      -      "title": "Result"
      -    }
      -  },
      -  "required": [
      -    "result"
      -  ],
      -  "title": "zia_user_group_managerOutput",
      -  "type": "object"
      -}New value: +null
  3. First observedv0.12.7

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description adds 'read-only' which aligns with the readOnlyHint annotation but provides no additional behavioral context. It does not disclose pagination, result ordering, or any potential side effects beyond the read-only nature. Given the annotation already covers safety, the description adds minimal value here.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, front-loaded sentence that efficiently conveys the tool's core functionality without any fluff. Every word earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has 9 optional parameters and no output schema, the one-line description is insufficient. It fails to mention return format, pagination behavior, default sorting, or any constraints, leaving the agent without critical operational context for correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The description maps three usage scenarios to parameters (group_id for 'fetch by ID', name for 'find by name', and no params for list) but does not explain the other six parameters (page, page_size, sort_by, sort_order, defined_by, search). With schema description coverage at only 11%, the description should compensate more for the missing parameter semantics, but it only partially does.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool reads ZIA user groups and enumerates three modes: fetch by ID, find by name, or list. This is specific and distinguishes it from sibling tools like get_zia_users and get_zia_user_departments, which target different resources.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

While the description indicates what the tool does, it offers no guidance on when to choose this tool over alternatives such as zid_get_user_groups or zid_get_user_groups_by_name. There is no mention of prerequisites, mutually exclusive modes, or when a particular mode is appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools