# marchward_get_decisions

Review recent governance decisions (the audit trail). Filter by agent, tool name, or outcome (ALLOW/BLOCK/ESCALATE). Use to verify governance is active or to investigate what an agent actually did.

Agent View of the PolicyLayer registry record for `marchward_get_decisions`. HTML page: https://policylayer.com/tools/ai-marchward-mcp-server/marchward-get-decisions

## Facts

- Tool: `marchward_get_decisions`
- Server: Mcp Server (`@marchward/mcp-server`) — https://policylayer.com/tools/ai-marchward-mcp-server.md
- Install: `npx -y @marchward/mcp-server`
- Homepage: https://github.com/marchward/marchward
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "marchward_get_decisions",
    "arguments": {}
  }
}
```

## Why marchward_get_decisions is rated Low

This tool retrieves and queries audit trail data with filtering capabilities (by agent, tool name, or outcome) but produces no side effects. It is a read-only inspection mechanism for reviewing historical governance decisions. The blast radius if misused is low—an agent could review audit logs to understand previous decisions, but cannot modify records, execute operations, delete data, or affect financial systems.

From the tool's own definition: "Tool description explicitly states 'Review recent governance decisions' and 'to verify governance is active or to investigate what an agent actually did.' The language 'review' and 'investigate' indicates read-only access to audit logs without modification or…"

## Use case

AI agents call marchward_get_decisions to retrieve information from Mcp Server without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "marchward_get_decisions": {}
  }
}
```

## Other tools on Mcp Server (6)

- `marchward_authorize` — Destructive — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-authorize.md
- `marchward_execute` — Execute — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-execute.md
- `marchward_check_coverage` — Read — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-check-coverage.md
- `marchward_list_agents` — Read — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-list-agents.md
- `marchward_bind_policy` — Write — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-bind-policy.md
- `marchward_register_agent` — Write — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-register-agent.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=ai-marchward-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/ai-marchward-mcp-server
