# create_action_rule

Створити тригер/правило дій для форми. Спрацьовує on_create/on_update і виконує: send_email, send_sms, update_record, redirect, show_message. Можна додати умови (conditions) і поля для оновлення (update_fields).

Agent View of the PolicyLayer registry record for `create_action_rule`. HTML page: https://policylayer.com/tools/com-quintadb-mcp/create-action-rule

## Facts

- Tool: `create_action_rule`
- Server: QuintaDB (`https://quintadb.com/mcp`) — https://policylayer.com/tools/com-quintadb-mcp.md
- Homepage: https://github.com/https://quintadb.com/mcp
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 12 (3 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `url` | string | no | URL для redirect |
| `name` | string | yes | Назва правила |
| `app_id` | string | yes | Project ID (from list_projects) |
| `emails` | string | no | Email отримувачів (через кому) |
| `message` | string | no | Текст повідомлення (для show_message) |
| `numbers` | string | no | Номери телефонів для SMS (через кому) |
| `subject` | string | no | Тема листа |
| `redirect` | boolean | no |  |
| `send_sms` | boolean | no |  |
| `sms_body` | string | no | Текст SMS |
| `entity_id` | string | yes | ID форми |
| `on_create` | boolean | no | Спрацьовує при створенні запису |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "create_action_rule",
    "arguments": {
      "name": "<name>",
      "app_id": "<app_id>",
      "entity_id": "<entity_id>"
    }
  }
}
```

## Why create_action_rule is rated Medium

This tool creates automation rules (triggers) that can send emails, send SMS, update records, and redirect users. Creating such rules is a Write operation (creating a new rule/configuration), but the blast radius is high because a misconfigured trigger could spam emails/SMS, mass-update records, or disrupt form workflows across the platform.

From the tool's own definition: "Створити тригер/правило дій для форми. Спрацьовує on_create/on_update і виконує: send_email, send_sms, update_record, redirect, show_message"

Risk signals: Accepts URL/endpoint input (url) · High parameter count (28 properties)

## Use case

AI agents use create_action_rule to create or update resources in QuintaDB, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your QuintaDB environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches QuintaDB:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "create_action_rule": {
      "limits": [
        {
          "counter": "create_action_rule_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on QuintaDB (115)

- `delete_few_records` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-few-records.md
- `delete_field` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-field.md
- `delete_form` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-form.md
- `delete_portal_group` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-portal-group.md
- `delete_portal_menu_item` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-portal-menu-item.md
- `delete_portal_user` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-portal-user.md
- `delete_project` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-project.md
- `delete_record` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-record.md
- `delete_records_by_filter` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-records-by-filter.md
- `delete_reminder` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-reminder.md
- `delete_saved_view` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-saved-view.md
- `delete_schedule` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-schedule.md
- `delete_team_group` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-team-group.md
- `delete_template` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-template.md
- `delete_webhook` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/delete-webhook.md
- `remove_user_from_portal_group` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/remove-user-from-portal-group.md
- `remove_user_from_team_group` — Destructive — https://policylayer.com/tools/com-quintadb-mcp/remove-user-from-team-group.md
- `run_action` — Execute — https://policylayer.com/tools/com-quintadb-mcp/run-action.md
- `check_ai_site_status` — Read — https://policylayer.com/tools/com-quintadb-mcp/check-ai-site-status.md
- `describe_project` — Read — https://policylayer.com/tools/com-quintadb-mcp/describe-project.md
- `export_records` — Read — https://policylayer.com/tools/com-quintadb-mcp/export-records.md
- `fetch_url` — Read — https://policylayer.com/tools/com-quintadb-mcp/fetch-url.md
- `get_column_total` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-column-total.md
- `get_field_types` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-field-types.md
- `get_form_fields` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-form-fields.md
- `get_form_settings` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-form-settings.md
- `get_metric` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-metric.md
- `get_portal_page` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-portal-page.md
- `get_project` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-project.md
- `get_quickstart_guide` — Read — https://policylayer.com/tools/com-quintadb-mcp/get-quickstart-guide.md
- …and 85 more: https://policylayer.com/tools/com-quintadb-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-quintadb-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-quintadb-mcp
