Critical-risk tools in Doit
29 of the 238 tools in Doit are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cancel_async_operationDestructiveManage Cloud Analytics reports and get reports data in JSON format. Cancels a pending or running async report operation. Already-terminal operations (succeeded, failed, canceled...
-
cancel_inviteDestructiveManage users who have access to the DoiT platform. Marks the invite as `Cancelled` and invalidates the invite token so any outstanding email links stop working. The invite docum...
-
confirm_actionDestructiveRuns a generated DELETE operation that another tool staged and returned as `status: "approval_required"` with a summary and a one-time approval token. Intended for use after the...
-
delete_account_roleDestructiveManage cloud provider connections and check feature availability for connected accounts. Deletes a CloudConnect document for an AWS account.
-
delete_alertDestructiveNotifications triggered when cloud costs exceed defined thresholds or meet specific conditions. Deletes the alert specified by the Id.
-
delete_allocationDestructiveDefine how costs are distributed across your organization. Deletes the allocation specified by the Id.
-
delete_annotationDestructiveCustom notes added to cost data to provide contextual information. Deletes the annotation specified by the Id.
-
delete_ava_conversationDestructiveInteract with Ava, DoiT's AI-powered cloud assistant. Deletes an Ava conversation by its ID.
-
delete_budgetDestructiveTrack actual cloud spend against planned spend. Deletes the specified budget.
-
delete_cloudflow_connectionDestructiveManage cloud provider connections used in CloudFlow workflows (AWS and GCP). Deletes a connection. Returns 409 if the connection is referenced by one or more flows.
-
delete_custom_themeDestructiveDeletes the custom theme specified by the Id. Requires Cloud Analytics Admin permission.
-
delete_customer_geographic_access_scopeDestructiveManage country-based access to tenants in your customer hierarchy. Clears the geographic scope for a target customer, leaving it unassigned. The authenticated tenant must be the...
-
delete_customer_groupDestructiveManage explicit, named groups of downstream customers and the users scoped to them. Deletes a customer group owned by the authenticated tenant. Groups with assigned users cannot...
-
delete_datahub_datasetDestructiveIngest third-party cost, usage, and metric-based data for analysis. Deletes a specific DataHub dataset.
-
delete_datahub_datasetsDestructiveIngest third-party cost, usage, and metric-based data for analysis. Deletes one or more DataHub datasets and all their associated data.
-
delete_datahub_events_by_filterDestructiveIngest third-party cost, usage, and metric-based data for analysis. Deletes specific events using filters. Note that the two filters, `eventIds` and `time ranges`, are mutually ...
-
delete_folderDestructiveOrganize Cloud Analytics resources (reports, allocations) into folders. Deletes the specified folder. All nested folders will be deleted. Any reports or allocations contained in...
-
delete_geographic_access_custom_regionDestructiveManage country-based access to tenants in your customer hierarchy. Deletes a custom region owned by the authenticated tenant. Assigned regions cannot be deleted. Requires the Us...
-
delete_insight_resultDestructiveManage cloud insights representing recommendations and findings for cloud resources. Permanently deletes a single insight and all its associated resource results. Only insights ...
-
delete_insight_resultsDestructiveManage cloud insights representing recommendations and findings for cloud resources. Deletes all insights matching the specified key from the batch source. This removes the insi...
-
delete_labelDestructiveCreate and manage labels to organize and categorize your cloud resources. Deletes the label specified by the Id.
-
delete_reportDestructiveManage Cloud Analytics reports and get reports data in JSON format. Deletes the specified Cloud Analytics report.
-
delete_roleDestructiveManage user permissions and access levels in your organization. Deletes a custom role. Preset roles cannot be deleted, and a role still assigned to users or groups must be unass...
-
delete_service_accountDestructiveManage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Permanently deletes a service account and all of its API tokens, which stop authe...
-
delete_service_account_tokenDestructiveManage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Permanently deletes an API token, which stops authenticating immediately. This ca...
-
delete_userDestructiveManage users who have access to the DoiT platform. Deletes a user.
-
delete_user_geographic_access_scopeDestructiveManage country-based access to tenants in your customer hierarchy. Clears the geographic scope assigned to a user who belongs to the target customer, leaving it unassigned. The ...
-
id_of_assetDestructiveManage cloud resources or services in your cloud environment. Updates an existing asset, such as G Suite/Workspace or Office 365 subscription, to add or remove licenses.
-
remove_ticket_tagsDestructiveCreate and manage support tickets with DoiT. Removes one or more tags from an existing support request. The operation is surgical — only the tags listed in the request are remov...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.