New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

Doit

238 tools. 102 can modify or destroy data without limits.

29 destructive tools with no built-in limits. Policy required.

Last updated:

102 can modify or destroy data
136 read-only
238 tools total

Community server · catalogue entry checked 07/10/2026 · full schemas captured for 228 of 238 tools

How to control Doit ↓

What Doit exposes to your agents

Read (136) Write / Execute (73) Destructive / Financial (29)

What Doit costs in tokens

85,570 tokens of tool definitions, loaded on every request
43% of a 200k context window
4,398 heaviest tool: async_run_inline
Critical Risk

The most dangerous Doit tools

102 of Doit's 238 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control Doit

PolicyLayer is an MCP gateway — it sits between your AI agents and Doit, and nothing reaches the server without passing your rules. These are the rules we recommend:

Deny destructive operations
{
  "cancel_async_operation": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "accept_budget_suggestion": {
    "limits": [
      {
        "counter": "accept_budget_suggestion_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "ask_ava_sync": {
    "limits": [
      {
        "counter": "ask_ava_sync_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register Doit — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON DOIT →

Instant setup, no code required.

All 238 Doit tools

DESTRUCTIVE 29 tools
Destructive cancel_async_operation Manage Cloud Analytics reports and get reports data in JSON format. Cancels a pending or running async report Destructive cancel_invite Manage users who have access to the DoiT platform. Marks the invite as Cancelled and invalidates the invite to Destructive confirm_action Runs a generated DELETE operation that another tool staged and returned as status: "approval_required" with a Destructive delete_account_role Manage cloud provider connections and check feature availability for connected accounts. Deletes a CloudConnec Destructive delete_alert Notifications triggered when cloud costs exceed defined thresholds or meet specific conditions. Deletes the al Destructive delete_allocation Define how costs are distributed across your organization. Deletes the allocation specified by the Id. Destructive delete_annotation Custom notes added to cost data to provide contextual information. Deletes the annotation specified by the Id. Destructive delete_ava_conversation Interact with Ava, DoiT's AI-powered cloud assistant. Deletes an Ava conversation by its ID. Destructive delete_budget Track actual cloud spend against planned spend. Deletes the specified budget. Destructive delete_cloudflow_connection Manage cloud provider connections used in CloudFlow workflows (AWS and GCP). Deletes a connection. Returns 409 Destructive delete_custom_theme Deletes the custom theme specified by the Id. Requires Cloud Analytics Admin permission. Destructive delete_customer_geographic_access_scope Manage country-based access to tenants in your customer hierarchy. Clears the geographic scope for a target cu Destructive delete_customer_group Manage explicit, named groups of downstream customers and the users scoped to them. Deletes a customer group o Destructive delete_datahub_dataset Ingest third-party cost, usage, and metric-based data for analysis. Deletes a specific DataHub dataset. Destructive delete_datahub_datasets Ingest third-party cost, usage, and metric-based data for analysis. Deletes one or more DataHub datasets and a Destructive delete_datahub_events_by_filter Ingest third-party cost, usage, and metric-based data for analysis. Deletes specific events using filters. Not Destructive delete_folder Organize Cloud Analytics resources (reports, allocations) into folders. Deletes the specified folder. All nest Destructive delete_geographic_access_custom_region Manage country-based access to tenants in your customer hierarchy. Deletes a custom region owned by the authen Destructive delete_insight_result Manage cloud insights representing recommendations and findings for cloud resources. Permanently deletes a sin Destructive delete_insight_results Manage cloud insights representing recommendations and findings for cloud resources. Deletes all insights matc Destructive delete_label Create and manage labels to organize and categorize your cloud resources. Deletes the label specified by the I Destructive delete_report Manage Cloud Analytics reports and get reports data in JSON format. Deletes the specified Cloud Analytics repo Destructive delete_role Manage user permissions and access levels in your organization. Deletes a custom role. Preset roles cannot be Destructive delete_service_account Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Permanently de Destructive delete_service_account_token Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Permanently de Destructive delete_user Manage users who have access to the DoiT platform. Deletes a user. Destructive delete_user_geographic_access_scope Manage country-based access to tenants in your customer hierarchy. Clears the geographic scope assigned to a u Destructive id_of_asset Manage cloud resources or services in your cloud environment. Updates an existing asset, such as G Suite/Works Destructive remove_ticket_tags Create and manage support tickets with DoiT. Removes one or more tags from an existing support request. The op
WRITE 64 tools
Write accept_budget_suggestion AI-generated budget recommendations you can accept (link to a budget you created) or dismiss. Marks the sugges Write add_ticket_tags Create and manage support tickets with DoiT. Adds one or more tags to an existing support request. The operati Write assign_contract_template Manage contract templates for PartnerOps resellers (T1/T2). Applies a contract template owned by the authentic Write assign_customer_group_user Manage explicit, named groups of downstream customers and the users scoped to them. Assigns a user to a custom Write assign_objects_to_label Use this when the user wants to assign or unassign DoiT console objects (reports, budgets, alerts, allocations Write create_account_role Manage cloud provider connections and check feature availability for connected accounts. Creates or updates a Write create_alert Use this when the user wants to set up a new cost alert with thresholds and notification settings. Changes app Write create_allocation Use this when the user wants to create a new cost allocation rule. Changes apply immediately. Do NOT use this Write create_annotation Use this when the user wants to add a new annotation to mark a specific date or event in cost data. Changes ap Write create_asset Manage cloud resources or services in your cloud environment. Creates a new asset. Write create_budget Use this when the user wants to create a new cloud budget with spending limits and alert thresholds. Requires Write create_cloudflow_connection Use this when the user wants to create a new CloudFlow cloud provider connection (a GCP or AWS account connect Write create_custom_theme Creates a new custom color theme. Requires Cloud Analytics Admin permission. Write create_customer_group Manage explicit, named groups of downstream customers and the users scoped to them. Creates a customer group o Write create_datahub_dataset Use this when the user wants to create a new DataHub dataset. Changes apply immediately. Do NOT use this for v Write create_folder Use this when the user wants to create a new Cloud Analytics folder to organize reports and allocations. A dup Write create_geographic_access_custom_region Manage country-based access to tenants in your customer hierarchy. Creates a custom region owned by the authen Write create_label Use this when the user wants to create a new DoiT console label for organizing analytics objects. Names must b Write create_report Use this when the user wants to save a new Cloud Analytics report with a specific configuration. Creates a new Write create_role Manage user permissions and access levels in your organization. Creates a custom role in the authenticated cus Write create_service_account Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Creates a serv Write create_service_account_token Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Mints an API t Write create_signup_request Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require Write create_signup_session Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require Write create_ticket Use this when the user wants to create a new support ticket. The ticket is opened with DoiT support immediatel Write create_ticket_comment Adds a comment to an existing support ticket. For customers, comments are always public. For DoiT employees, c Write datahub_import_provider_records Ingest third-party cost, usage, and metric-based data for analysis. Sends provider-native records as JSON inst Write export_cloud_diagram_json Cloud Diagrams visualize your cloud infrastructure and resource relationships. Exports the full content of a d Write export_cloudflow_flow Manage CloudFlow. Serializes the flow — plus every flow it references through subflow nodes — into a tenant-ne Write export_datahub_dataset_records Ingest third-party cost, usage, and metric-based data for analysis. Returns one page of the live records of a Write import_cloudflow_flow Manage CloudFlow. Creates every flow of a previously exported bundle in the authenticated tenant. Imports are Write invite_user Use this when the user wants to invite a new person to the organization. The invitation email is sent immediat Write patch_anomaly Monitor cost spikes in your cloud environment. Updates the review status of the anomaly identified by {id}, th Write post_insight_resource_results Manage cloud insights representing recommendations and findings for cloud resources. Replaces all resource res Write post_insight_result Use this when the user wants to create a new custom insight or update an existing one's metadata (title, descr Write post_insight_results Manage cloud insights representing recommendations and findings for cloud resources. Creates or updates multip Write reassign_shared_payer_account Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a Write resend_invite Manage users who have access to the DoiT platform. Resets the invite expiry to 48 hours from now, invalidates Write send_datahub_events Use this when the user wants to send DataHub events for ingestion (1–50,000 events per call). Each event requi Write set_active_theme Use this when the user wants to change the authenticated user’s active Cloud Analytics color theme. Accepts a Write unassign_customer_group_user Manage explicit, named groups of downstream customers and the users scoped to them. Unassigns a user from a cu Write update_alert Use this when the user wants to modify an existing cost alert. Supports partial updates, including name-only, Write update_allocation Use this when the user wants to modify an existing cost allocation. Omitted fields are preserved. Use rule for Write update_annotation Use this when the user wants to modify an existing annotation. Nonempty content is required on every update. O Write update_aws_feature Manage cloud provider connections and check feature availability for connected accounts. Updates an AWS featur Write update_budget Use this when the user wants to modify an existing budget. Supports partial updates; omitted fields retain the Write update_cloudflow_connection Updates a CloudFlow connection immediately using connectionId and the last observed ETag (ifMatch). A stale ET Write update_customer Read and update your organization's general settings. Partially updates the general settings and contact info Write update_customer_geographic_access_scope Manage country-based access to tenants in your customer hierarchy. Atomically replaces the geographic scope fo Write update_customer_group Manage explicit, named groups of downstream customers and the users scoped to them. Updates the name, customer Write update_datahub_dataset Use this when the user wants to modify an existing DataHub dataset's description, displayName, or logoName. Th Write update_folder Use this when the user wants to rename, re-describe, or move (reparent) an existing Cloud Analytics folder. Ch Write update_geographic_access_custom_region Manage country-based access to tenants in your customer hierarchy. Updates the name, country membership, or bo Write update_insight_status Use this when the user wants to change the display status of an existing insight (e.g. mark it acknowledged, i Write update_label Use this when the user wants to modify an existing custom DoiT console label. Requires Cloud Analytics Admin; Write update_report Use this when the user wants to modify an existing saved Cloud Analytics report. Only custom reports the calle Write update_resource_permissions Use this when the user wants to change who a Cloud Analytics resource is shared with or update access levels. Write update_role Manage user permissions and access levels in your organization. Updates the name, description and/or permissio Write update_service_account Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Partially upda Write update_service_account_token Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Moves the toke Write update_theme Use this when the user wants to modify an existing custom color theme — rename it, change its primary color, o Write update_ticket Create and manage support tickets with DoiT. Partially updates a support request. Supports setting the request Write update_user Use this when the user wants to update a user's information such as name, job function, phone, language, or ro Write update_user_geographic_access_scope Manage country-based access to tenants in your customer hierarchy. Atomically replaces the geographic scope as
READ 136 tools
Read ask_ava_sync Ask DoiT AVA, DoiT's AI assistant for cloud cost and infrastructure, a question about the user's DoiT account, Read ava_feedback Interact with Ava, DoiT's AI-powered cloud assistant. Submit feedback on an Ava answer to help improve respons Read compare_spend Use this when the user wants to compare spend between two time periods (e.g. 'Compare the latest three months Read cost_breakdown Use this when the user wants a simple cost breakdown by service, project, or cloud provider (e.g. 'What are my Read cost_trend Use this when the user wants to see monthly spend over time (e.g. 'Show me my cost trend', 'How has my spend c Read datahub_events_csv_file Ingest third-party cost, usage, and metric-based data for analysis. Sends a batch of events to DataHub using a Read dismiss_budget_suggestion AI-generated budget recommendations you can accept (link to a budget you created) or dismiss. Marks the sugges Read find_cloud_diagrams Use this when the user wants to find architecture diagrams or cloud infrastructure diagrams. Matches cloud res Read get_active_theme Use this when the user wants to know which color theme is currently active for the authenticated user (the the Read get_alert Use this when the user wants to view the details of a specific cost alert. Accepts either the alert ID or a pa Read get_allocation Use this when the user wants to view details of a specific cost allocation. Accepts either the allocation ID o Read get_annotation Use this when the user wants to view details of a specific annotation. Accepts either the annotation ID or a p Read get_anomalies Use this when the user wants to check for unexpected cost spikes, billing anomalies, or unusual spending patte Read get_anomaly Use this when the user wants to view details of a specific cost anomaly by its ID. Returns full anomaly data i Read get_anomaly_explanation Monitor cost spikes in your cloud environment. Returns a likely-cause explanation for the specified anomaly, a Read get_asset Use this when the user wants to view details of a specific cloud asset. Accepts an asset ID, which takes prece Read get_async_operation Manage Cloud Analytics reports and get reports data in JSON format. Returns the current status of an async rep Read get_async_operation_results Manage Cloud Analytics reports and get reports data in JSON format. Returns the result of a succeeded async re Read get_aws_account Use this when the user wants the CloudConnect details of a specific connected AWS account, such as its IAM rol Read get_aws_member_account Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read get_aws_organization Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read get_aws_recommendation Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read get_billing_explainer_per_payer Explain month-over-month changes in invoiced cloud costs. Returns the invoiced cost changes for each payer in Read get_billing_transfer_program_management_accounts_status Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customer Read get_budget Use this when the user wants to view the details and current utilization of a specific budget. Accepts either Read get_cloud_connect_supported_features Use this when the user wants to know which DoiT CloudConnect features a connected AWS account supports and whe Read get_cloud_diagram_components Use this when the user wants to discover all cloud infrastructure diagrams and their layers (statussheets), or Read get_cloud_diagram_cost_snapshot Use this when the user wants a cost snapshot for a specific cloud infrastructure diagram layer over a time per Read get_cloud_diagram_layer_snapshot Cloud Diagrams visualize your cloud infrastructure and resource relationships. Returns a single snapshot of th Read get_cloud_diagram_resource_relationships Use this when the user wants to understand how a specific resource in a cloud infrastructure diagram is connec Read get_cloud_diagrams_stats Use this when the user wants activity statistics for their cloud infrastructure diagrams over a time period — Read get_cloud_incident Use this when the user wants to view details of a specific cloud platform incident. Accepts either the inciden Read get_cloud_incidents Use this when the user wants to check for active cloud platform outages, service disruptions, or incidents fro Read get_cloud_overview Use this when the user wants a high-level overview or dashboard of their entire cloud infrastructure. Returns Read get_cloudflow_connection Use this when the user wants to view the details of a specific CloudFlow cloud provider connection by its ID, Read get_cloudflow_flow_run Manage CloudFlow. Returns a run's status and, for each node, the JSON it consumed and produced. This is how yo Read get_cloudflow_template Use this when the user wants to view the details of a specific CloudFlow template by its ID, including its nam Read get_commitment Returns details of a specific spend commitment contract for Google Cloud, AWS, or Azure, identified by its ID. Read get_commitment_policy Cloud-agnostic PerfectScale for Commitments resources — commitment policies shared by AWS and GCP. Returns one Read get_contract List and manage tenant-scoped contracts as a T1/T2 PartnerOps caller. Returns the specified contract. Read get_contract_template Manage contract templates for PartnerOps resellers (T1/T2). Returns a single contract template owned by the au Read get_customer Read and update your organization's general settings. Returns the customer, including its general settings and Read get_customer_geographic_access_scope Manage country-based access to tenants in your customer hierarchy. Returns the geographic scope for a target c Read get_customer_group Manage explicit, named groups of downstream customers and the users scoped to them. Returns a customer group o Read get_datahub_dataset Use this when the user wants to view details of a specific DataHub dataset by its name. Returns dataset metada Read get_dimension Use this when the valid filter values for a specific dimension are needed, such as for a run_query filter, or Read get_entity_invoice_explainer Explain month-over-month changes in invoiced cloud costs. Returns invoiced cost changes for an invoice owned b Read get_folder Use this when the user wants to view details of a specific Cloud Analytics folder. Accepts either the folder I Read get_gcp_billing_account Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read get_gcp_recommendation Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read get_geographic_access_custom_region Manage country-based access to tenants in your customer hierarchy. Returns a custom region owned by the authen Read get_insight Use this when the user wants the details and aggregate summary (savings, risk counts, status, description) of Read get_insight_resources Use this when the user wants to see which specific resources are affected by an optimization insight. Returns Read get_invoice Use this when the user wants to view details of a specific invoice by its ID. Returns full invoice data includ Read get_label Use this when the user wants to view details of a specific DoiT console label (not a cloud resource label). Ac Read get_label_assignments Use this when the user wants to see which DoiT console objects are assigned to a label. Returns objectId and o Read get_report_config Get the configuration of a specific Cloud Analytics report by ID. Returns the stored report object including n Read get_report_results Use this when the user wants to retrieve the data results of a specific saved report. Uses the report's saved Read get_resource_permissions Use this when the user wants to see who a Cloud Analytics resource is shared with and at what access level. Re Read get_role Manage user permissions and access levels in your organization. Returns a single role by ID. Preset roles are Read get_service_account Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns a serv Read get_service_account_token Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns one AP Read get_signup_request Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require Read get_statussheet_components Cloud Diagrams visualize your cloud infrastructure and resource relationships. Returns the specified component Read get_theme Use this when the user wants to view details of a specific custom color theme. Accepts either the custom theme Read get_ticket Returns details of a specific support ticket from the DoiT API by its ID. Read get_user_geographic_access_scope Manage country-based access to tenants in your customer hierarchy. Returns the geographic scope assigned to a Read get_widget Beta. Read precomputed current-month cloud spend and forecast metrics. Widget results are refreshed in the bac Read list_account_team Use this when the user wants to know who their DoiT account team / account managers are. Returns the list of a Read list_alert_slack_channels Notifications triggered when cloud costs exceed defined thresholds or meet specific conditions. Lists Slack de Read list_alerts Use this when the user wants to see their cost alerts or check alert configurations. Returns a paginated list Read list_allocations Use this when the user wants to see their cost allocation rules or configurations. Returns a list of allocatio Read list_annotations Use this when the user wants to see calendar annotations or notes on cost data. Returns a list of annotations. Read list_assets Use this when the user wants to browse their cloud assets, subscriptions, or resources. Returns a paginated li Read list_aws_member_accounts Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_aws_organizations Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_aws_organizations_settings Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_aws_planned_purchases Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_aws_recommendations Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_aws_reserved_instances Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_aws_savings_plans Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_billing_transfer_end_customers Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customer Read list_billing_transfer_end_customers_by_reseller Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customer Read list_billing_transfer_program_management_accounts Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customer Read list_billing_transfer_reseller_accounts Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customer Read list_billing_transfer_reseller_accounts_with_tenants Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customer Read list_budget_suggestions AI-generated budget recommendations you can accept (link to a budget you created) or dismiss. Returns the pend Read list_budgets Use this when the user wants to see their cloud spending budgets or check budget status. Returns a paginated l Read list_cloud_diagram_activity_groups Use this when the user wants the activity history of a cloud diagram layer. Without tags, returns ALARM, COMMI Read list_cloud_diagram_layer_snapshots Cloud Diagrams visualize your cloud infrastructure and resource relationships. Returns the list of saved snaps Read list_cloud_diagram_node_activities Use this when the user wants the change history of a single component node in a cloud diagram layer. Returns i Read list_cloudflow_connections Use this when the user wants to see their CloudFlow cloud provider connections (the GCP/AWS accounts connected Read list_cloudflow_flow_runs Manage CloudFlow. Returns a flow's runs, newest first. Use mode to separate test runs from production ones — t Read list_cloudflow_templates Use this when the user wants to see the catalogue of available CloudFlow templates (read-only blueprints they Read list_cloudflows Use this when the user wants to see their CloudFlow automation flows. Returns a cursor-paginated list of flows Read list_commitment_policies Cloud-agnostic PerfectScale for Commitments resources — commitment policies shared by AWS and GCP. Returns eve Read list_commitments Returns a paginated list of spend commitment contracts from the DoiT Commitment Manager for Google Cloud, AWS, Read list_contract_templates Manage contract templates for PartnerOps resellers (T1/T2). Lists contract templates owned by the authenticate Read list_contracts List and manage tenant-scoped contracts as a T1/T2 PartnerOps caller. Lists the contracts held by the specifie Read list_customer_group_users Manage explicit, named groups of downstream customers and the users scoped to them. Returns the users assigned Read list_customer_groups Manage explicit, named groups of downstream customers and the users scoped to them. Returns the ready customer Read list_datahub_datasets Use this when the user wants to see available DataHub datasets. Returns a list of datasets with metadata. Do N Read list_dimensions Use this when the user wants to see available dimensions for cost analysis queries. Returns id, label and type Read list_folders Use this when the user wants to see their Cloud Analytics folders, which organize reports and allocations into Read list_gcp_billing_accounts Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_gcp_billing_accounts_settings Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_gcp_planned_purchases Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_gcp_recommendations Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_gcp_resource_cuds Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_gcp_spend_cuds Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Read list_geographic_access_countries Manage country-based access to tenants in your customer hierarchy. Returns the canonical ISO 3166-1 alpha-2 co Read list_geographic_access_custom_regions Manage country-based access to tenants in your customer hierarchy. Returns the ready custom regions owned by t Read list_invoices Use this when the user wants to see their invoices, check billing history, or review payment records. Returns Read list_labels Use this when the user wants to see their DoiT console labels for organizing reports, budgets, alerts, allocat Read list_optimization_recommendations Use this when the user asks about optimization, recommendations, insights, savings opportunities, rightsizing, Read list_organizations Use this when the user wants to see the organizations in their DoiT account. Returns a list of organizations. Read list_platforms Use this when the user wants to see the support-ticket platform catalog. Returns platform IDs and display name Read list_products Use this when the user wants to see the support-ticket product catalog. Returns product IDs, display names, an Read list_reports Use this when the user wants to see their saved Cloud Analytics reports or browse available reports. Returns p Read list_roles Use this when the user wants to see available roles in their DoiT organization. Returns a list of roles with p Read list_service_account_tokens Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns the se Read list_service_accounts Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns every Read list_service_quotas Monitor cloud service quota usage across connected accounts and projects. Returns the latest service quota usa Read list_shared_payer_account_mappings Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a Read list_shared_payer_management_accounts Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a Read list_shared_payers Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a Read list_themes Use this when the user wants to see the custom color themes defined for their account, which control the color Read list_ticket_comments Returns all comments on a support ticket. For customers, only public comments are returned. For DoiT employees Read list_ticket_tags Create and manage support tickets with DoiT. Returns the tags currently set on a support request. DoiT employ Read list_tickets Use this when the user wants to view their support tickets, check ticket status, or review open issues. Return Read list_users Use this when the user wants to see users in their DoiT organization or check who has access. Includes active Read list_widgets Beta. Read precomputed current-month cloud spend and forecast metrics. Widget results are refreshed in the bac Read search_cloud_diagrams Use this when the user wants to search their cloud infrastructure diagrams and components by name or property. Read test_run_cloudflow_flow Manage CloudFlow. Runs a flow once as a test, and accepts an unpublished (draft) flow — unlike actions/trigger Read validate_user Use this when the user asks to verify their account connection or check who they are logged in as. Returns the Read verify_signup_request Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about Doit

Can an AI agent delete data through the Doit MCP server? +

Yes. The Doit server exposes 29 destructive tools including cancel_async_operation, cancel_invite, confirm_action. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through Doit? +

The Doit server has 64 write tools including accept_budget_suggestion, add_ticket_tags, assign_contract_template. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach Doit.

How many tools does the Doit MCP server expose? +

238 tools across 4 categories: Destructive, Execute, Read, Write. 136 are read-only. 102 can modify, create, or delete data.

How do I enforce a policy on Doit? +

Register the Doit MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every Doit tool call.

Deterministic rules across all 238 Doit tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Instant setup, no code required.

238 Doit tools catalogued and risk-classified — across an index of 46,500+ MCP servers.

// WHERE THIS COMES FROM

These policies come from Doit's registry record.

The record behind this page: verified identity, auth posture, risk grade, every tool classified, recommended policy — re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.