# get_policy

Gets a policy for a given enterprise and policy ID. Requires the resource name in the format: enterprises/{enterpriseId}/policies/{policyId}.

Agent View of the PolicyLayer registry record for `get_policy`. HTML page: https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/get-policy

## Facts

- Tool: `get_policy`
- Server: Android Management API (`https://androidmanagement.googleapis.com/mcp`) — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp.md
- Homepage: https://github.com/https://androidmanagement.googleapis.com/mcp
- Risk category: Read (Low risk)
- Registry record: grade C, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 1
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | no | The name of the policy in the form `enterprises/{enterpriseId}/policies/{policyId}`. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_policy",
    "arguments": {}
  }
}
```

## Why get_policy is rated Low

This tool retrieves policy configuration data for an enterprise without side effects. While the Android Management API controls sensitive enterprise resources, the get_policy action itself is read-only and poses minimal risk compared to tools that could deploy policies, modify device settings, or execute commands. The blast radius is limited to information disclosure of policy metadata.

From the tool's own definition: "Tool name is 'get_policy' and description states 'Gets a policy' — a retrieval operation with no modification, deletion, or execution semantics. The resource is queried by ID with a GET-like pattern."

## Use case

AI agents call get_policy to retrieve information from Android Management API without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Android Management API:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "get_policy": {}
  }
}
```

## Other tools on Android Management API (8)

- `get_application` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/get-application.md
- `get_device` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/get-device.md
- `get_enterprise` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/get-enterprise.md
- `get_web_app` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/get-web-app.md
- `list_devices` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/list-devices.md
- `list_enterprises` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/list-enterprises.md
- `list_policies` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/list-policies.md
- `list_web_apps` — Read — https://policylayer.com/tools/com-googleapis-androidmanagement-mcp/list-web-apps.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-googleapis-androidmanagement-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-googleapis-androidmanagement-mcp
