# Doit MCP server

Agent View of the PolicyLayer registry record for Doit: identity, probed posture, risk grade, and all 238 tools classified. HTML page: https://policylayer.com/tools/doit

## Facts

- Server id: `@doitintl/doit-mcp-server`
- Install: `npx -y @doitintl/doit-mcp-server`
- Homepage: https://www.npmjs.com/package/@doitintl/doit-mcp-server
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 238 (228 with introspected schema)
- Tool categories present: Destructive, Execute, Read, Write
- Context-window cost: 85570 tokens per request — https://policylayer.com/token-cost/doit
- Tags: doit, admin, automation
- Record last modified: 2026-10-07T07:53:54.242Z

## Tools (238)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `cancel_async_operation` | Destructive | Critical | https://policylayer.com/tools/doit/cancel-async-operation.md |
| `cancel_invite` | Destructive | Critical | https://policylayer.com/tools/doit/cancel-invite.md |
| `confirm_action` | Destructive | Critical | https://policylayer.com/tools/doit/confirm-action.md |
| `delete_account_role` | Destructive | Critical | https://policylayer.com/tools/doit/delete-account-role.md |
| `delete_alert` | Destructive | Critical | https://policylayer.com/tools/doit/delete-alert.md |
| `delete_allocation` | Destructive | Critical | https://policylayer.com/tools/doit/delete-allocation.md |
| `delete_annotation` | Destructive | Critical | https://policylayer.com/tools/doit/delete-annotation.md |
| `delete_ava_conversation` | Destructive | Critical | https://policylayer.com/tools/doit/delete-ava-conversation.md |
| `delete_budget` | Destructive | Critical | https://policylayer.com/tools/doit/delete-budget.md |
| `delete_cloudflow_connection` | Destructive | Critical | https://policylayer.com/tools/doit/delete-cloudflow-connection.md |
| `delete_custom_theme` | Destructive | Critical | https://policylayer.com/tools/doit/delete-custom-theme.md |
| `delete_customer_geographic_access_scope` | Destructive | Critical | https://policylayer.com/tools/doit/delete-customer-geographic-access-scope.md |
| `delete_customer_group` | Destructive | Critical | https://policylayer.com/tools/doit/delete-customer-group.md |
| `delete_datahub_dataset` | Destructive | Critical | https://policylayer.com/tools/doit/delete-datahub-dataset.md |
| `delete_datahub_datasets` | Destructive | Critical | https://policylayer.com/tools/doit/delete-datahub-datasets.md |
| `delete_datahub_events_by_filter` | Destructive | Critical | https://policylayer.com/tools/doit/delete-datahub-events-by-filter.md |
| `delete_folder` | Destructive | Critical | https://policylayer.com/tools/doit/delete-folder.md |
| `delete_geographic_access_custom_region` | Destructive | Critical | https://policylayer.com/tools/doit/delete-geographic-access-custom-region.md |
| `delete_insight_result` | Destructive | Critical | https://policylayer.com/tools/doit/delete-insight-result.md |
| `delete_insight_results` | Destructive | Critical | https://policylayer.com/tools/doit/delete-insight-results.md |
| `delete_label` | Destructive | Critical | https://policylayer.com/tools/doit/delete-label.md |
| `delete_report` | Destructive | Critical | https://policylayer.com/tools/doit/delete-report.md |
| `delete_role` | Destructive | Critical | https://policylayer.com/tools/doit/delete-role.md |
| `delete_service_account` | Destructive | Critical | https://policylayer.com/tools/doit/delete-service-account.md |
| `delete_service_account_token` | Destructive | Critical | https://policylayer.com/tools/doit/delete-service-account-token.md |
| `delete_user` | Destructive | Critical | https://policylayer.com/tools/doit/delete-user.md |
| `delete_user_geographic_access_scope` | Destructive | Critical | https://policylayer.com/tools/doit/delete-user-geographic-access-scope.md |
| `id_of_asset` | Destructive | Critical | https://policylayer.com/tools/doit/id-of-asset.md |
| `remove_ticket_tags` | Destructive | Critical | https://policylayer.com/tools/doit/remove-ticket-tags.md |
| `async_run_inline` | Execute | High | https://policylayer.com/tools/doit/async-run-inline.md |
| `async_run_report_by_id` | Execute | High | https://policylayer.com/tools/doit/async-run-report-by-id.md |
| `build_cloud_flow` | Execute | High | https://policylayer.com/tools/doit/build-cloud-flow.md |
| `refine_cloudflow` | Execute | High | https://policylayer.com/tools/doit/refine-cloudflow.md |
| `resend_signup_verification` | Execute | High | https://policylayer.com/tools/doit/resend-signup-verification.md |
| `run_query` | Execute | High | https://policylayer.com/tools/doit/run-query.md |
| `stop_cloudflow_flow` | Execute | High | https://policylayer.com/tools/doit/stop-cloudflow-flow.md |
| `trigger_cloud_flow` | Execute | High | https://policylayer.com/tools/doit/trigger-cloud-flow.md |
| `trigger_cloudflow_flow` | Execute | High | https://policylayer.com/tools/doit/trigger-cloudflow-flow.md |
| `ask_ava_sync` | Read | Low | https://policylayer.com/tools/doit/ask-ava-sync.md |
| `ava_feedback` | Read | Low | https://policylayer.com/tools/doit/ava-feedback.md |
| `compare_spend` | Read | Low | https://policylayer.com/tools/doit/compare-spend.md |
| `cost_breakdown` | Read | Low | https://policylayer.com/tools/doit/cost-breakdown.md |
| `cost_trend` | Read | Low | https://policylayer.com/tools/doit/cost-trend.md |
| `datahub_events_csv_file` | Read | Low | https://policylayer.com/tools/doit/datahub-events-csv-file.md |
| `dismiss_budget_suggestion` | Read | Low | https://policylayer.com/tools/doit/dismiss-budget-suggestion.md |
| `find_cloud_diagrams` | Read | Low | https://policylayer.com/tools/doit/find-cloud-diagrams.md |
| `get_active_theme` | Read | Low | https://policylayer.com/tools/doit/get-active-theme.md |
| `get_alert` | Read | Low | https://policylayer.com/tools/doit/get-alert.md |
| `get_allocation` | Read | Low | https://policylayer.com/tools/doit/get-allocation.md |
| `get_annotation` | Read | Low | https://policylayer.com/tools/doit/get-annotation.md |
| `get_anomalies` | Read | Low | https://policylayer.com/tools/doit/get-anomalies.md |
| `get_anomaly` | Read | Low | https://policylayer.com/tools/doit/get-anomaly.md |
| `get_anomaly_explanation` | Read | Low | https://policylayer.com/tools/doit/get-anomaly-explanation.md |
| `get_asset` | Read | Low | https://policylayer.com/tools/doit/get-asset.md |
| `get_async_operation` | Read | Low | https://policylayer.com/tools/doit/get-async-operation.md |
| `get_async_operation_results` | Read | Low | https://policylayer.com/tools/doit/get-async-operation-results.md |
| `get_aws_account` | Read | Low | https://policylayer.com/tools/doit/get-aws-account.md |
| `get_aws_member_account` | Read | Low | https://policylayer.com/tools/doit/get-aws-member-account.md |
| `get_aws_organization` | Read | Low | https://policylayer.com/tools/doit/get-aws-organization.md |
| `get_aws_recommendation` | Read | Low | https://policylayer.com/tools/doit/get-aws-recommendation.md |
| `get_billing_explainer_per_payer` | Read | Low | https://policylayer.com/tools/doit/get-billing-explainer-per-payer.md |
| `get_billing_transfer_program_management_accounts_status` | Read | Low | https://policylayer.com/tools/doit/get-billing-transfer-program-management-accounts-status.md |
| `get_budget` | Read | Low | https://policylayer.com/tools/doit/get-budget.md |
| `get_cloud_connect_supported_features` | Read | Low | https://policylayer.com/tools/doit/get-cloud-connect-supported-features.md |
| `get_cloud_diagram_components` | Read | Low | https://policylayer.com/tools/doit/get-cloud-diagram-components.md |
| `get_cloud_diagram_cost_snapshot` | Read | Low | https://policylayer.com/tools/doit/get-cloud-diagram-cost-snapshot.md |
| `get_cloud_diagram_layer_snapshot` | Read | Low | https://policylayer.com/tools/doit/get-cloud-diagram-layer-snapshot.md |
| `get_cloud_diagram_resource_relationships` | Read | Low | https://policylayer.com/tools/doit/get-cloud-diagram-resource-relationships.md |
| `get_cloud_diagrams_stats` | Read | Low | https://policylayer.com/tools/doit/get-cloud-diagrams-stats.md |
| `get_cloud_incident` | Read | Low | https://policylayer.com/tools/doit/get-cloud-incident.md |
| `get_cloud_incidents` | Read | Low | https://policylayer.com/tools/doit/get-cloud-incidents.md |
| `get_cloud_overview` | Read | Low | https://policylayer.com/tools/doit/get-cloud-overview.md |
| `get_cloudflow_connection` | Read | Low | https://policylayer.com/tools/doit/get-cloudflow-connection.md |
| `get_cloudflow_flow_run` | Read | Low | https://policylayer.com/tools/doit/get-cloudflow-flow-run.md |
| `get_cloudflow_template` | Read | Low | https://policylayer.com/tools/doit/get-cloudflow-template.md |
| `get_commitment` | Read | Low | https://policylayer.com/tools/doit/get-commitment.md |
| `get_commitment_policy` | Read | Low | https://policylayer.com/tools/doit/get-commitment-policy.md |
| `get_contract` | Read | Low | https://policylayer.com/tools/doit/get-contract.md |
| `get_contract_template` | Read | Low | https://policylayer.com/tools/doit/get-contract-template.md |
| `get_customer` | Read | Low | https://policylayer.com/tools/doit/get-customer.md |
| `get_customer_geographic_access_scope` | Read | Low | https://policylayer.com/tools/doit/get-customer-geographic-access-scope.md |
| `get_customer_group` | Read | Low | https://policylayer.com/tools/doit/get-customer-group.md |
| `get_datahub_dataset` | Read | Low | https://policylayer.com/tools/doit/get-datahub-dataset.md |
| `get_dimension` | Read | Low | https://policylayer.com/tools/doit/get-dimension.md |
| `get_entity_invoice_explainer` | Read | Low | https://policylayer.com/tools/doit/get-entity-invoice-explainer.md |
| `get_folder` | Read | Low | https://policylayer.com/tools/doit/get-folder.md |
| `get_gcp_billing_account` | Read | Low | https://policylayer.com/tools/doit/get-gcp-billing-account.md |
| `get_gcp_recommendation` | Read | Low | https://policylayer.com/tools/doit/get-gcp-recommendation.md |
| `get_geographic_access_custom_region` | Read | Low | https://policylayer.com/tools/doit/get-geographic-access-custom-region.md |
| `get_insight` | Read | Low | https://policylayer.com/tools/doit/get-insight.md |
| `get_insight_resources` | Read | Low | https://policylayer.com/tools/doit/get-insight-resources.md |
| `get_invoice` | Read | Low | https://policylayer.com/tools/doit/get-invoice.md |
| `get_label` | Read | Low | https://policylayer.com/tools/doit/get-label.md |
| `get_label_assignments` | Read | Low | https://policylayer.com/tools/doit/get-label-assignments.md |
| `get_report_config` | Read | Low | https://policylayer.com/tools/doit/get-report-config.md |
| `get_report_results` | Read | Low | https://policylayer.com/tools/doit/get-report-results.md |
| `get_resource_permissions` | Read | Low | https://policylayer.com/tools/doit/get-resource-permissions.md |
| `get_role` | Read | Low | https://policylayer.com/tools/doit/get-role.md |
| `get_service_account` | Read | Low | https://policylayer.com/tools/doit/get-service-account.md |
| `get_service_account_token` | Read | Low | https://policylayer.com/tools/doit/get-service-account-token.md |
| `get_signup_request` | Read | Low | https://policylayer.com/tools/doit/get-signup-request.md |
| `get_statussheet_components` | Read | Low | https://policylayer.com/tools/doit/get-statussheet-components.md |
| `get_theme` | Read | Low | https://policylayer.com/tools/doit/get-theme.md |
| `get_ticket` | Read | Low | https://policylayer.com/tools/doit/get-ticket.md |
| `get_user_geographic_access_scope` | Read | Low | https://policylayer.com/tools/doit/get-user-geographic-access-scope.md |
| `get_widget` | Read | Low | https://policylayer.com/tools/doit/get-widget.md |
| `list_account_team` | Read | Low | https://policylayer.com/tools/doit/list-account-team.md |
| `list_alert_slack_channels` | Read | Low | https://policylayer.com/tools/doit/list-alert-slack-channels.md |
| `list_alerts` | Read | Low | https://policylayer.com/tools/doit/list-alerts.md |
| `list_allocations` | Read | Low | https://policylayer.com/tools/doit/list-allocations.md |
| `list_annotations` | Read | Low | https://policylayer.com/tools/doit/list-annotations.md |
| `list_assets` | Read | Low | https://policylayer.com/tools/doit/list-assets.md |
| `list_aws_member_accounts` | Read | Low | https://policylayer.com/tools/doit/list-aws-member-accounts.md |
| `list_aws_organizations` | Read | Low | https://policylayer.com/tools/doit/list-aws-organizations.md |
| `list_aws_organizations_settings` | Read | Low | https://policylayer.com/tools/doit/list-aws-organizations-settings.md |
| `list_aws_planned_purchases` | Read | Low | https://policylayer.com/tools/doit/list-aws-planned-purchases.md |
| `list_aws_recommendations` | Read | Low | https://policylayer.com/tools/doit/list-aws-recommendations.md |
| `list_aws_reserved_instances` | Read | Low | https://policylayer.com/tools/doit/list-aws-reserved-instances.md |
| `list_aws_savings_plans` | Read | Low | https://policylayer.com/tools/doit/list-aws-savings-plans.md |
| `list_billing_transfer_end_customers` | Read | Low | https://policylayer.com/tools/doit/list-billing-transfer-end-customers.md |
| `list_billing_transfer_end_customers_by_reseller` | Read | Low | https://policylayer.com/tools/doit/list-billing-transfer-end-customers-by-reseller.md |
| `list_billing_transfer_program_management_accounts` | Read | Low | https://policylayer.com/tools/doit/list-billing-transfer-program-management-accounts.md |
| `list_billing_transfer_reseller_accounts` | Read | Low | https://policylayer.com/tools/doit/list-billing-transfer-reseller-accounts.md |
| `list_billing_transfer_reseller_accounts_with_tenants` | Read | Low | https://policylayer.com/tools/doit/list-billing-transfer-reseller-accounts-with-tenants.md |
| `list_budget_suggestions` | Read | Low | https://policylayer.com/tools/doit/list-budget-suggestions.md |
| `list_budgets` | Read | Low | https://policylayer.com/tools/doit/list-budgets.md |
| `list_cloud_diagram_activity_groups` | Read | Low | https://policylayer.com/tools/doit/list-cloud-diagram-activity-groups.md |
| `list_cloud_diagram_layer_snapshots` | Read | Low | https://policylayer.com/tools/doit/list-cloud-diagram-layer-snapshots.md |
| `list_cloud_diagram_node_activities` | Read | Low | https://policylayer.com/tools/doit/list-cloud-diagram-node-activities.md |
| `list_cloudflow_connections` | Read | Low | https://policylayer.com/tools/doit/list-cloudflow-connections.md |
| `list_cloudflow_flow_runs` | Read | Low | https://policylayer.com/tools/doit/list-cloudflow-flow-runs.md |
| `list_cloudflow_templates` | Read | Low | https://policylayer.com/tools/doit/list-cloudflow-templates.md |
| `list_cloudflows` | Read | Low | https://policylayer.com/tools/doit/list-cloudflows.md |
| `list_commitment_policies` | Read | Low | https://policylayer.com/tools/doit/list-commitment-policies.md |
| `list_commitments` | Read | Low | https://policylayer.com/tools/doit/list-commitments.md |
| `list_contract_templates` | Read | Low | https://policylayer.com/tools/doit/list-contract-templates.md |
| `list_contracts` | Read | Low | https://policylayer.com/tools/doit/list-contracts.md |
| `list_customer_group_users` | Read | Low | https://policylayer.com/tools/doit/list-customer-group-users.md |
| `list_customer_groups` | Read | Low | https://policylayer.com/tools/doit/list-customer-groups.md |
| `list_datahub_datasets` | Read | Low | https://policylayer.com/tools/doit/list-datahub-datasets.md |
| `list_dimensions` | Read | Low | https://policylayer.com/tools/doit/list-dimensions.md |
| `list_folders` | Read | Low | https://policylayer.com/tools/doit/list-folders.md |
| `list_gcp_billing_accounts` | Read | Low | https://policylayer.com/tools/doit/list-gcp-billing-accounts.md |
| `list_gcp_billing_accounts_settings` | Read | Low | https://policylayer.com/tools/doit/list-gcp-billing-accounts-settings.md |
| `list_gcp_planned_purchases` | Read | Low | https://policylayer.com/tools/doit/list-gcp-planned-purchases.md |
| `list_gcp_recommendations` | Read | Low | https://policylayer.com/tools/doit/list-gcp-recommendations.md |
| `list_gcp_resource_cuds` | Read | Low | https://policylayer.com/tools/doit/list-gcp-resource-cuds.md |
| `list_gcp_spend_cuds` | Read | Low | https://policylayer.com/tools/doit/list-gcp-spend-cuds.md |
| `list_geographic_access_countries` | Read | Low | https://policylayer.com/tools/doit/list-geographic-access-countries.md |
| `list_geographic_access_custom_regions` | Read | Low | https://policylayer.com/tools/doit/list-geographic-access-custom-regions.md |
| `list_invoices` | Read | Low | https://policylayer.com/tools/doit/list-invoices.md |
| `list_labels` | Read | Low | https://policylayer.com/tools/doit/list-labels.md |
| `list_optimization_recommendations` | Read | Low | https://policylayer.com/tools/doit/list-optimization-recommendations.md |
| `list_organizations` | Read | Low | https://policylayer.com/tools/doit/list-organizations.md |
| `list_platforms` | Read | Low | https://policylayer.com/tools/doit/list-platforms.md |
| `list_products` | Read | Low | https://policylayer.com/tools/doit/list-products.md |
| `list_reports` | Read | Low | https://policylayer.com/tools/doit/list-reports.md |
| `list_roles` | Read | Low | https://policylayer.com/tools/doit/list-roles.md |
| `list_service_account_tokens` | Read | Low | https://policylayer.com/tools/doit/list-service-account-tokens.md |
| `list_service_accounts` | Read | Low | https://policylayer.com/tools/doit/list-service-accounts.md |
| `list_service_quotas` | Read | Low | https://policylayer.com/tools/doit/list-service-quotas.md |
| `list_shared_payer_account_mappings` | Read | Low | https://policylayer.com/tools/doit/list-shared-payer-account-mappings.md |
| `list_shared_payer_management_accounts` | Read | Low | https://policylayer.com/tools/doit/list-shared-payer-management-accounts.md |
| `list_shared_payers` | Read | Low | https://policylayer.com/tools/doit/list-shared-payers.md |
| `list_themes` | Read | Low | https://policylayer.com/tools/doit/list-themes.md |
| `list_ticket_comments` | Read | Low | https://policylayer.com/tools/doit/list-ticket-comments.md |
| `list_ticket_tags` | Read | Low | https://policylayer.com/tools/doit/list-ticket-tags.md |
| `list_tickets` | Read | Low | https://policylayer.com/tools/doit/list-tickets.md |
| `list_users` | Read | Low | https://policylayer.com/tools/doit/list-users.md |
| `list_widgets` | Read | Low | https://policylayer.com/tools/doit/list-widgets.md |
| `search_cloud_diagrams` | Read | Low | https://policylayer.com/tools/doit/search-cloud-diagrams.md |
| `test_run_cloudflow_flow` | Read | Low | https://policylayer.com/tools/doit/test-run-cloudflow-flow.md |
| `validate_user` | Read | Low | https://policylayer.com/tools/doit/validate-user.md |
| `verify_signup_request` | Read | Low | https://policylayer.com/tools/doit/verify-signup-request.md |
| `accept_budget_suggestion` | Write | Medium | https://policylayer.com/tools/doit/accept-budget-suggestion.md |
| `add_ticket_tags` | Write | Medium | https://policylayer.com/tools/doit/add-ticket-tags.md |
| `assign_contract_template` | Write | Medium | https://policylayer.com/tools/doit/assign-contract-template.md |
| `assign_customer_group_user` | Write | Medium | https://policylayer.com/tools/doit/assign-customer-group-user.md |
| `assign_objects_to_label` | Write | Medium | https://policylayer.com/tools/doit/assign-objects-to-label.md |
| `create_account_role` | Write | Medium | https://policylayer.com/tools/doit/create-account-role.md |
| `create_alert` | Write | Medium | https://policylayer.com/tools/doit/create-alert.md |
| `create_allocation` | Write | Medium | https://policylayer.com/tools/doit/create-allocation.md |
| `create_annotation` | Write | Medium | https://policylayer.com/tools/doit/create-annotation.md |
| `create_asset` | Write | Medium | https://policylayer.com/tools/doit/create-asset.md |
| `create_budget` | Write | Medium | https://policylayer.com/tools/doit/create-budget.md |
| `create_cloudflow_connection` | Write | Medium | https://policylayer.com/tools/doit/create-cloudflow-connection.md |
| `create_custom_theme` | Write | Medium | https://policylayer.com/tools/doit/create-custom-theme.md |
| `create_customer_group` | Write | Medium | https://policylayer.com/tools/doit/create-customer-group.md |
| `create_datahub_dataset` | Write | Medium | https://policylayer.com/tools/doit/create-datahub-dataset.md |
| `create_folder` | Write | Medium | https://policylayer.com/tools/doit/create-folder.md |
| `create_geographic_access_custom_region` | Write | Medium | https://policylayer.com/tools/doit/create-geographic-access-custom-region.md |
| `create_label` | Write | Medium | https://policylayer.com/tools/doit/create-label.md |
| `create_report` | Write | Medium | https://policylayer.com/tools/doit/create-report.md |
| `create_role` | Write | Medium | https://policylayer.com/tools/doit/create-role.md |
| `create_service_account` | Write | Medium | https://policylayer.com/tools/doit/create-service-account.md |
| `create_service_account_token` | Write | Medium | https://policylayer.com/tools/doit/create-service-account-token.md |
| `create_signup_request` | Write | Medium | https://policylayer.com/tools/doit/create-signup-request.md |
| `create_signup_session` | Write | Medium | https://policylayer.com/tools/doit/create-signup-session.md |
| `create_ticket` | Write | Medium | https://policylayer.com/tools/doit/create-ticket.md |
| `create_ticket_comment` | Write | Medium | https://policylayer.com/tools/doit/create-ticket-comment.md |
| `datahub_import_provider_records` | Write | Medium | https://policylayer.com/tools/doit/datahub-import-provider-records.md |
| `export_cloud_diagram_json` | Write | Medium | https://policylayer.com/tools/doit/export-cloud-diagram-json.md |
| `export_cloudflow_flow` | Write | Medium | https://policylayer.com/tools/doit/export-cloudflow-flow.md |
| `export_datahub_dataset_records` | Write | Medium | https://policylayer.com/tools/doit/export-datahub-dataset-records.md |
| `import_cloudflow_flow` | Write | Medium | https://policylayer.com/tools/doit/import-cloudflow-flow.md |
| `invite_user` | Write | Medium | https://policylayer.com/tools/doit/invite-user.md |
| `patch_anomaly` | Write | Medium | https://policylayer.com/tools/doit/patch-anomaly.md |
| `post_insight_resource_results` | Write | Medium | https://policylayer.com/tools/doit/post-insight-resource-results.md |
| `post_insight_result` | Write | Medium | https://policylayer.com/tools/doit/post-insight-result.md |
| `post_insight_results` | Write | Medium | https://policylayer.com/tools/doit/post-insight-results.md |
| `reassign_shared_payer_account` | Write | Medium | https://policylayer.com/tools/doit/reassign-shared-payer-account.md |
| `resend_invite` | Write | Medium | https://policylayer.com/tools/doit/resend-invite.md |
| `send_datahub_events` | Write | Medium | https://policylayer.com/tools/doit/send-datahub-events.md |
| `set_active_theme` | Write | Medium | https://policylayer.com/tools/doit/set-active-theme.md |
| `unassign_customer_group_user` | Write | Medium | https://policylayer.com/tools/doit/unassign-customer-group-user.md |
| `update_alert` | Write | Medium | https://policylayer.com/tools/doit/update-alert.md |
| `update_allocation` | Write | Medium | https://policylayer.com/tools/doit/update-allocation.md |
| `update_annotation` | Write | Medium | https://policylayer.com/tools/doit/update-annotation.md |
| `update_aws_feature` | Write | Medium | https://policylayer.com/tools/doit/update-aws-feature.md |
| `update_budget` | Write | Medium | https://policylayer.com/tools/doit/update-budget.md |
| `update_cloudflow_connection` | Write | Medium | https://policylayer.com/tools/doit/update-cloudflow-connection.md |
| `update_customer` | Write | Medium | https://policylayer.com/tools/doit/update-customer.md |
| `update_customer_geographic_access_scope` | Write | Medium | https://policylayer.com/tools/doit/update-customer-geographic-access-scope.md |
| `update_customer_group` | Write | Medium | https://policylayer.com/tools/doit/update-customer-group.md |
| `update_datahub_dataset` | Write | Medium | https://policylayer.com/tools/doit/update-datahub-dataset.md |
| `update_folder` | Write | Medium | https://policylayer.com/tools/doit/update-folder.md |
| `update_geographic_access_custom_region` | Write | Medium | https://policylayer.com/tools/doit/update-geographic-access-custom-region.md |
| `update_insight_status` | Write | Medium | https://policylayer.com/tools/doit/update-insight-status.md |
| `update_label` | Write | Medium | https://policylayer.com/tools/doit/update-label.md |
| `update_report` | Write | Medium | https://policylayer.com/tools/doit/update-report.md |
| `update_resource_permissions` | Write | Medium | https://policylayer.com/tools/doit/update-resource-permissions.md |
| `update_role` | Write | Medium | https://policylayer.com/tools/doit/update-role.md |
| `update_service_account` | Write | Medium | https://policylayer.com/tools/doit/update-service-account.md |
| `update_service_account_token` | Write | Medium | https://policylayer.com/tools/doit/update-service-account-token.md |
| `update_theme` | Write | Medium | https://policylayer.com/tools/doit/update-theme.md |
| `update_ticket` | Write | Medium | https://policylayer.com/tools/doit/update-ticket.md |
| `update_user` | Write | Medium | https://policylayer.com/tools/doit/update-user.md |
| `update_user_geographic_access_scope` | Write | Medium | https://policylayer.com/tools/doit/update-user-geographic-access-scope.md |

## Tool descriptions

- `cancel_async_operation` — Manage Cloud Analytics reports and get reports data in JSON format. Cancels a pending or running async report operation. Already-terminal operations (succeeded, failed, canceled) are returned as-is without any state change (idempotent). …
- `cancel_invite` — Manage users who have access to the DoiT platform. Marks the invite as Cancelled and invalidates the invite token so any outstanding email links stop working. The invite document is retained (soft cancel) — the user row remains visible i…
- `confirm_action` — Runs a generated DELETE operation that another tool staged and returned as status: "approval_required" with a summary and a one-time approval token. Intended for use after the user approves that summary. A token that is never confirmed e…
- `delete_account_role` — Manage cloud provider connections and check feature availability for connected accounts. Deletes a CloudConnect document for an AWS account.
- `delete_alert` — Notifications triggered when cloud costs exceed defined thresholds or meet specific conditions. Deletes the alert specified by the Id.
- `delete_allocation` — Define how costs are distributed across your organization. Deletes the allocation specified by the Id.
- `delete_annotation` — Custom notes added to cost data to provide contextual information. Deletes the annotation specified by the Id.
- `delete_ava_conversation` — Interact with Ava, DoiT's AI-powered cloud assistant. Deletes an Ava conversation by its ID.
- `delete_budget` — Track actual cloud spend against planned spend. Deletes the specified budget.
- `delete_cloudflow_connection` — Manage cloud provider connections used in CloudFlow workflows (AWS and GCP). Deletes a connection. Returns 409 if the connection is referenced by one or more flows.
- `delete_custom_theme` — Deletes the custom theme specified by the Id. Requires Cloud Analytics Admin permission.
- `delete_customer_geographic_access_scope` — Manage country-based access to tenants in your customer hierarchy. Clears the geographic scope for a target customer, leaving it unassigned. The authenticated tenant must be the hierarchy root, and the target must be that root customer o…
- `delete_customer_group` — Manage explicit, named groups of downstream customers and the users scoped to them. Deletes a customer group owned by the authenticated tenant. Groups with assigned users cannot be deleted. Requires the UsersManager permission.
- `delete_datahub_dataset` — Ingest third-party cost, usage, and metric-based data for analysis. Deletes a specific DataHub dataset.
- `delete_datahub_datasets` — Ingest third-party cost, usage, and metric-based data for analysis. Deletes one or more DataHub datasets and all their associated data.
- `delete_datahub_events_by_filter` — Ingest third-party cost, usage, and metric-based data for analysis. Deletes specific events using filters. Note that the two filters, eventIds and time ranges, are mutually exclusive.
- `delete_folder` — Organize Cloud Analytics resources (reports, allocations) into folders. Deletes the specified folder. All nested folders will be deleted. Any reports or allocations contained in the folder are moved to the root.
- `delete_geographic_access_custom_region` — Manage country-based access to tenants in your customer hierarchy. Deletes a custom region owned by the authenticated tenant. Assigned regions cannot be deleted. Requires the UsersManager permission.
- `delete_insight_result` — Manage cloud insights representing recommendations and findings for cloud resources. Permanently deletes a single insight and all its associated resource results. Only insights created via the public API can be deleted.
- `delete_insight_results` — Manage cloud insights representing recommendations and findings for cloud resources. Deletes all insights matching the specified key from the batch source. This removes the insight and all its associated resource results. For single-insi…
- `delete_label` — Create and manage labels to organize and categorize your cloud resources. Deletes the label specified by the Id.
- `delete_report` — Manage Cloud Analytics reports and get reports data in JSON format. Deletes the specified Cloud Analytics report.
- `delete_role` — Manage user permissions and access levels in your organization. Deletes a custom role. Preset roles cannot be deleted, and a role still assigned to users or groups must be unassigned first. A service account of a parent tenant can delete…
- `delete_service_account` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Permanently deletes a service account and all of its API tokens, which stop authenticating immediately. Deleting an ID that no longer exists …
- `delete_service_account_token` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Permanently deletes an API token, which stops authenticating immediately. This cannot be undone. Deleting an ID that no longer exists returns…
- `delete_user` — Manage users who have access to the DoiT platform. Deletes a user.
- `delete_user_geographic_access_scope` — Manage country-based access to tenants in your customer hierarchy. Clears the geographic scope assigned to a user who belongs to the target customer, leaving it unassigned. The authenticated tenant must be the hierarchy root, and the tar…
- `id_of_asset` — Manage cloud resources or services in your cloud environment. Updates an existing asset, such as G Suite/Workspace or Office 365 subscription, to add or remove licenses.
- `remove_ticket_tags` — Create and manage support tickets with DoiT. Removes one or more tags from an existing support request. The operation is surgical — only the tags listed in the request are removed; tags not listed are preserved. Removing a tag that is no…
- `async_run_inline` — Manage Cloud Analytics reports and get reports data in JSON format. Submits an async report execution job using an inline configuration. Returns 202 immediately with a Location header pointing to the operation status endpoint. Requires t…
- `async_run_report_by_id` — Manage Cloud Analytics reports and get reports data in JSON format. Submits an async execution job for a saved report identified by ID. Returns 202 immediately with a Location header pointing to the operation status endpoint. Requires th…
- `build_cloud_flow` — Use this when the user wants to build a brand-new CloudFlow automation from scratch using natural language. Creates the draft before planning, so flowId can be returned even if the builder stops early. Streams progress and returns flowId…
- `refine_cloudflow` — Refines an existing CloudFlow using natural language. Streams progress and returns the answer and conversationId; normally no flowId is returned. A plan or clarification question may save nothing. Reusing conversationId continues that co…
- `resend_signup_verification` — Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothing until the organization's admin verifies the request. Agen…
- `run_query` — Use this when the user wants to analyze cloud costs, generate a cost breakdown, view spending trends, or run a custom analytics query across their cloud providers. Runs the config through the DoiT Cloud Analytics API query endpoint (http…
- `stop_cloudflow_flow` — Manage CloudFlow. Stops the run currently in progress for the given flow. The run is identified from the flow alone — no run ID is needed, since a flow can only have one run active at a time. No Idempotency-Key is required. This is a sta…
- `trigger_cloud_flow` — Triggers a published CloudFlow with a webhook trigger by flow ID or trigger URL. Executes real actions immediately and returns executionLink. Drafts fail with 403, flows without a webhook trigger with 400, and already-running flows with …
- `trigger_cloudflow_flow` — Manage CloudFlow. Starts a run of a published flow whose first node is a webhook, scheduled, or manual trigger. A draft flow is rejected with 422 — use actions/test-run to run one. No Idempotency-Key is required. This is a state transiti…
- `ask_ava_sync` — Ask DoiT AVA, DoiT's AI assistant for cloud cost and infrastructure, a question about the user's DoiT account, cloud spending, anomalies, or optimization opportunities. AVA has access to the customer's billing data, usage patterns, and D…
- `ava_feedback` — Interact with Ava, DoiT's AI-powered cloud assistant. Submit feedback on an Ava answer to help improve response quality.
- `compare_spend` — Use this when the user wants to compare spend between two time periods (e.g. 'Compare the latest three months including this month with January through March'). Period 1 is N-1 full calendar months plus current month-to-date; period 2 is…
- `cost_breakdown` — Use this when the user wants a simple cost breakdown by service, project, or cloud provider (e.g. 'What are my top services by cost?', 'Which projects cost the most?'). Selects the top-N groups by total cost across the range and returns …
- `cost_trend` — Use this when the user wants to see monthly spend over time (e.g. 'Show me my cost trend', 'How has my spend changed over the last 6 months?'). Returns monthly cost data points, optionally broken down by service/project/cloud. The last p…
- `datahub_events_csv_file` — Ingest third-party cost, usage, and metric-based data for analysis. Sends a batch of events to DataHub using a CSV file, either uncompressed or compressed in ZIP or GZ format. It may take up to 15 minutes for the data to become available…
- `dismiss_budget_suggestion` — AI-generated budget recommendations you can accept (link to a budget you created) or dismiss. Marks the suggestion as dismissed so it no longer appears in the pending list.
- `find_cloud_diagrams` — Use this when the user wants to find architecture diagrams or cloud infrastructure diagrams. Matches cloud resource IDs (cld_id or props.id) and returns diagram viewer URLs and image URLs. Creates a sheet filter and queues image renderin…
- `get_active_theme` — Use this when the user wants to know which color theme is currently active for the authenticated user (the theme applied to Cloud Analytics reports). Returns the active theme id; the reserved sentinel "default" means no custom or preset …
- `get_alert` — Use this when the user wants to view the details of a specific cost alert. Accepts either the alert ID or a partial name (case-insensitive). Do NOT use this for listing all alerts (use list_alerts) or anomalies (use get_anomalies).
- `get_allocation` — Use this when the user wants to view details of a specific cost allocation. Accepts either the allocation ID or a case-insensitive partial name. Name lookup searches only the first 200 allocations; multiple matches return an error listin…
- `get_annotation` — Use this when the user wants to view details of a specific annotation. Accepts either the annotation ID or a partial content match (case-insensitive) within the first 200 annotations. Multiple matches return an ambiguity error listing co…
- `get_anomalies` — Use this when the user wants to check for unexpected cost spikes, billing anomalies, or unusual spending patterns. Returns recent anomalies with severity and impact. Do NOT use this for optimization recommendations or savings opportuniti…
- `get_anomaly` — Use this when the user wants to view details of a specific cost anomaly by its ID. Returns full anomaly data including affected resources and cost impact. Do NOT use this for listing all anomalies (use get_anomalies).
- `get_anomaly_explanation` — Monitor cost spikes in your cloud environment. Returns a likely-cause explanation for the specified anomaly, alongside the deterministic facts and evidence references it was generated from. The explanation itself is AI-generated; it is a…
- `get_asset` — Use this when the user wants to view details of a specific cloud asset. Accepts an asset ID, which takes precedence over name, or a case-insensitive partial name lookup within the first 249 assets only. Multiple name matches return an am…
- `get_async_operation` — Manage Cloud Analytics reports and get reports data in JSON format. Returns the current status of an async report operation. Non-terminal operations (pending, running) include a Retry-After header suggesting when to poll again. This endp…
- `get_async_operation_results` — Manage Cloud Analytics reports and get reports data in JSON format. Returns the result of a succeeded async report operation, including report metadata (id, reportName, owner, type, createTime, updateTime, urlUI) when the operation was s…
- `get_aws_account` — Use this when the user wants the CloudConnect details of a specific connected AWS account, such as its IAM role ARN, S3 bucket for real-time data, and which DoiT features are enabled or supported. Requires the 12-digit AWS account ID. Do…
- `get_aws_member_account` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns a single member AWS account with the same list-item fields as List member accounts, plus the Overview time…
- `get_aws_organization` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns a single AWS organization with the same list-item fields as List AWS Organizations, plus the Overview time…
- `get_aws_recommendation` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns the recommendation for one commitment type (serviceId) on the AWS organization, including analysis metrics…
- `get_billing_explainer_per_payer` — Explain month-over-month changes in invoiced cloud costs. Returns the invoiced cost changes for each payer in the authenticated tenant.
- `get_billing_transfer_program_management_accounts_status` — Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customers, and list program management accounts. Lightweight polling surface for the onboarding wizard: returns each of the caller's PM…
- `get_budget` — Use this when the user wants to view the details and current utilization of a specific budget. Accepts either the budget ID or a partial name (case-insensitive). Do NOT use this for listing all budgets (use list_budgets) or cost analysis…
- `get_cloud_connect_supported_features` — Use this when the user wants to know which DoiT CloudConnect features a connected AWS account supports and whether the account currently has the required permissions for each feature. Accepts a 12-digit AWS account ID, including AWS stan…
- `get_cloud_diagram_components` — Use this when the user wants to discover all cloud infrastructure diagrams and their layers (statussheets), or to look up layer IDs needed for other diagram endpoints. With no filters, returns accessible application and infrastructure di…
- `get_cloud_diagram_cost_snapshot` — Use this when the user wants a cost snapshot for a specific cloud infrastructure diagram layer over a time period — the API-reported total, trendingPct as a percentage (25 means 25%, null when no prior value is available), the top five r…
- `get_cloud_diagram_layer_snapshot` — Cloud Diagrams visualize your cloud infrastructure and resource relationships. Returns a single snapshot of the specified diagram layer identified by its ID.
- `get_cloud_diagram_resource_relationships` — Use this when the user wants to understand how a specific resource in a cloud infrastructure diagram is connected to other resources — its upstream/downstream edges and optional group membership (only when kind is group_members or both).…
- `get_cloud_diagrams_stats` — Use this when the user wants activity statistics for their cloud infrastructure diagrams over a time period — node create/update/delete change counts grouped by cloud service, plus each diagram's import/sync state. Useful for change audi…
- `get_cloud_incident` — Use this when the user wants to view details of a specific cloud platform incident. Accepts either the incident ID or a partial title match (case-insensitive). Do NOT use this for listing all incidents (use get_cloud_incidents) or anomal…
- `get_cloud_incidents` — Use this when the user wants to check for active cloud platform outages, service disruptions, or incidents from AWS or Google Cloud. Both active and archived incidents are included unless status is filtered. Do NOT use this for cost anom…
- `get_cloud_overview` — Use this when the user wants a high-level overview or dashboard of their entire cloud infrastructure. Returns cost by cloud provider, top services per cloud, top projects per cloud, recent cost anomalies, and recent cloud incidents — all…
- `get_cloudflow_connection` — Use this when the user wants to view the details of a specific CloudFlow cloud provider connection by its ID, including its GCP/AWS configuration, collaborators, and status. Do NOT use this to list all connections (use list_cloudflow_con…
- `get_cloudflow_flow_run` — Manage CloudFlow. Returns a run's status and, for each node, the JSON it consumed and produced. This is how you find out *why* a run failed, or that it "succeeded" while producing the wrong data. input is null for most node types, and th…
- `get_cloudflow_template` — Use this when the user wants to view the details of a specific CloudFlow template by its ID, including its name, description, and configuration instructions. Do NOT use this to list all templates (use list_cloudflow_templates) or to trig…
- `get_commitment` — Returns details of a specific spend commitment contract for Google Cloud, AWS, or Azure, identified by its ID. Includes the full breakdown of commitment periods, per-period contracted values, and current spend attainment against the comm…
- `get_commitment_policy` — Cloud-agnostic PerfectScale for Commitments resources — commitment policies shared by AWS and GCP. Returns one commitment policy by id, with its creation and last-update times and the list of account × product-line scopes it is explicitl…
- `get_contract` — List and manage tenant-scoped contracts as a T1/T2 PartnerOps caller. Returns the specified contract.
- `get_contract_template` — Manage contract templates for PartnerOps resellers (T1/T2). Returns a single contract template owned by the authenticated tenant (from the bearer token). Requires ContractTemplatesAdmin, DoiT API access (platform:externalApi), and the ch…
- `get_customer` — Read and update your organization's general settings. Returns the customer, including its general settings and contact info, scoped to {customerId}. {customerId} must match the customer resolved from the bearer token; a token scoped to a…
- `get_customer_geographic_access_scope` — Manage country-based access to tenants in your customer hierarchy. Returns the geographic scope for a target customer. The authenticated tenant must be the hierarchy root, and the target must be that root customer or one of its child cus…
- `get_customer_group` — Manage explicit, named groups of downstream customers and the users scoped to them. Returns a customer group owned by the authenticated tenant. Requires the UsersManager permission.
- `get_datahub_dataset` — Use this when the user wants to view details of a specific DataHub dataset by its name. Returns dataset metadata, including the schemaTemplate identifier when present, rather than the full column schema. Do NOT use this for listing all d…
- `get_dimension` — Use this when the valid filter values for a specific dimension are needed, such as for a run_query filter, or when the user wants to view dimension details. Returns id, label, type and all available value/cloud pairs in one response, wit…
- `get_entity_invoice_explainer` — Explain month-over-month changes in invoiced cloud costs. Returns invoiced cost changes for an invoice owned by the specified billing profile in the authenticated tenant.
- `get_folder` — Use this when the user wants to view details of a specific Cloud Analytics folder. Accepts either the folder ID or a case-insensitive partial name. Name lookup searches only the first 200 folders; multiple matches return an error listing…
- `get_gcp_billing_account` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns a single GCP Billing Account with the same list-item fields as List GCP Billing Accounts, plus the Overvie…
- `get_gcp_recommendation` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns the recommendation for one product line (gcp_service) and region scope on the GCP billing account, includi…
- `get_geographic_access_custom_region` — Manage country-based access to tenants in your customer hierarchy. Returns a custom region owned by the authenticated tenant. Requires the UsersManager permission.
- `get_insight` — Use this when the user wants the details and aggregate summary (savings, risk counts, status, description) of a single optimization insight identified by its source and key. Returns the insight metadata only — it does NOT include the ind…
- `get_insight_resources` — Use this when the user wants to see which specific resources are affected by an optimization insight. Returns a page of resourceResults with rowCount and pageToken, resource IDs, accounts, savings or risk counts. There is no dedicated re…
- `get_invoice` — Use this when the user wants to view details of a specific invoice by its ID. Returns full invoice data including line items and status. Do NOT use this for listing all invoices (use list_invoices) or cost analysis (use run_query).
- `get_label` — Use this when the user wants to view details of a specific DoiT console label (not a cloud resource label). Accepts either the label ID or a case-insensitive partial name. Name lookup searches only the first 200 labels; multiple matches …
- `get_label_assignments` — Use this when the user wants to see which DoiT console objects are assigned to a label. Returns objectId and objectType pairs, without object details. Do NOT use this for viewing label details (use get_label) or allocations (use list_all…
- `get_report_config` — Get the configuration of a specific Cloud Analytics report by ID. Returns the stored report object including name, type, and a nested 'config' field containing data source, metrics, dimensions, time range, filters, and visualization sett…
- `get_report_results` — Use this when the user wants to retrieve the data results of a specific saved report. Uses the report's saved time range, resolved at execution for relative ranges. Accepts an ID or a case-insensitive substring name lookup within the fir…
- `get_resource_permissions` — Use this when the user wants to see who a Cloud Analytics resource is shared with and at what access level. Returns the sharing settings (per-user roles and public visibility) for a specific alert, budget, report, or allocation. Requires…
- `get_role` — Manage user permissions and access levels in your organization. Returns a single role by ID. Preset roles are visible to every customer; a custom role is returned only to the customer that owns it. A service account of a parent tenant ca…
- `get_service_account` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns a service account owned by the authenticated customer; an ID that belongs to another customer returns 404. The ETag response header c…
- `get_service_account_token` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns one API token of the service account; an ID that belongs to another customer returns 404. accessToken is not included — it is shown o…
- `get_signup_request` — Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothing until the organization's admin verifies the request. Agen…
- `get_statussheet_components` — Cloud Diagrams visualize your cloud infrastructure and resource relationships. Returns the specified components of a diagram layer. Provide at least one component type with one or more IDs in the request body (for example, node or element).
- `get_theme` — Use this when the user wants to view details of a specific custom color theme. Accepts either the custom theme ID or a partial name (case-insensitive) across all custom themes. Multiple matches return an error listing names; id takes pre…
- `get_ticket` — Returns details of a specific support ticket from the DoiT API by its ID.
- `get_user_geographic_access_scope` — Manage country-based access to tenants in your customer hierarchy. Returns the geographic scope assigned to a user who belongs to the target customer. The authenticated tenant must be the hierarchy root, and the target must be that root …
- `get_widget` — Beta. Read precomputed current-month cloud spend and forecast metrics. Widget results are refreshed in the background; reading a widget returns the latest cached result and never starts a synchronous refresh. Use the list operation to di…
- `list_account_team` — Use this when the user wants to know who their DoiT account team / account managers are. Returns the list of account managers assigned to the customer, including name, email, role, and Calendly scheduling link. Do NOT use this for listin…
- `list_alert_slack_channels` — Notifications triggered when cloud costs exceed defined thresholds or meet specific conditions. Lists Slack destinations eligible for Alert notifications for the authenticated customer and caller. Returns canonical identifiers for recipi…
- `list_alerts` — Use this when the user wants to see their cost alerts or check alert configurations. Returns a paginated list of alerts. Do NOT use this for anomaly detection (use get_anomalies) or budget tracking (use list_budgets).
- `list_allocations` — Use this when the user wants to see their cost allocation rules or configurations. Returns a list of allocations. Returns pages of 40; pass the returned pageToken for another page (null means no next page). The case-insensitive partial n…
- `list_annotations` — Use this when the user wants to see calendar annotations or notes on cost data. Returns a list of annotations. Do NOT use this for labels (use list_labels) or alerts (use list_alerts).
- `list_assets` — Use this when the user wants to browse their cloud assets, subscriptions, or resources. Returns a paginated list of assets. Name filtering is case-insensitive and applies only to the returned page. The API cursor and unfiltered rowCount …
- `list_aws_member_accounts` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns all member AWS accounts under the specified AWS organization that have active or historical commitment cov…
- `list_aws_organizations` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns all AWS organizations (accounts) accessible to the authenticated tenant. Use as the entry point to discove…
- `list_aws_organizations_settings` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns one item per onboarded AWS organization. Each item includes that AWS organization's commitments purchasing…
- `list_aws_planned_purchases` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns planned purchases (laddering projections) for the AWS organization. One item per commitment type that has …
- `list_aws_recommendations` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns commitment purchase recommendations for the AWS organization, keyed by commitment type (compute, database)…
- `list_aws_reserved_instances` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns a paginated list of Reserved Instances (RIs) for the specified AWS organization. Optionally filter by stat…
- `list_aws_savings_plans` — Evaluate current AWS commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns a paginated list of Savings Plans for the specified AWS organization. Optionally filter by plan type (type…
- `list_billing_transfer_end_customers` — Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customers, and list program management accounts. Lists the end-customer AWS account mappings under a reseller's program management acco…
- `list_billing_transfer_end_customers_by_reseller` — Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customers, and list program management accounts. Same result as GET /billingtransfer/v1/end-customers, identified by resellerPmaAccount…
- `list_billing_transfer_program_management_accounts` — Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customers, and list program management accounts. Lists the caller's program management accounts (PMAs) and the reseller tenants mapped …
- `list_billing_transfer_reseller_accounts` — Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customers, and list program management accounts. Lists every reseller program management account (RPMA) node belonging to the calling r…
- `list_billing_transfer_reseller_accounts_with_tenants` — Manage AWS billing-transfer mappings between distributors and resellers and between resellers and end customers, and list program management accounts. Lists every reseller PMA node belonging to the calling reseller, each with the end-cus…
- `list_budget_suggestions` — AI-generated budget recommendations you can accept (link to a budget you created) or dismiss. Returns the pending AI-generated budget suggestions for your account. The set is small (a handful of pending suggestions) and is returned in fu…
- `list_budgets` — Use this when the user wants to see their cloud spending budgets or check budget status. Returns a paginated list of budgets with names, amounts, and utilization. Do NOT use this for cost analysis (use run_query) or spending alerts (use …
- `list_cloud_diagram_activity_groups` — Use this when the user wants the activity history of a cloud diagram layer. Without tags, returns ALARM, COMMIT, EVENT, and SNAPSHOT activity groups for the given layer (ss_id), ordered by timestamp descending; snapshot groups reference …
- `list_cloud_diagram_layer_snapshots` — Cloud Diagrams visualize your cloud infrastructure and resource relationships. Returns the list of saved snapshots for the specified diagram layer.
- `list_cloud_diagram_node_activities` — Use this when the user wants the change history of a single component node in a cloud diagram layer. Returns individual activity records (NODE_CREATE/NODE_UPDATE/NODE_DELETE) for the given node (ss_id + nodeId), ordered by timestamp desc…
- `list_cloudflow_connections` — Use this when the user wants to see their CloudFlow cloud provider connections (the GCP/AWS accounts connected for automation). Returns a cursor-paginated list of connections with their config and status. Do NOT use this to trigger a flo…
- `list_cloudflow_flow_runs` — Manage CloudFlow. Returns a flow's runs, newest first. Use mode to separate test runs from production ones — test runs are included by default. Per-node detail is not included here; fetch a single run to read what each node consumed and …
- `list_cloudflow_templates` — Use this when the user wants to see the catalogue of available CloudFlow templates (read-only blueprints they can build a flow from). Returns a cursor-paginated list of templates with their id, name, description, and instructions. Do NOT…
- `list_cloudflows` — Use this when the user wants to see their CloudFlow automation flows. Returns a cursor-paginated list of flows with their metadata, status, and last execution info.
- `list_commitment_policies` — Cloud-agnostic PerfectScale for Commitments resources — commitment policies shared by AWS and GCP. Returns every commitment policy available to the tenant: the three built-in policies (conservative, balanced, max_savings) followed by the…
- `list_commitments` — Returns a paginated list of spend commitment contracts from the DoiT Commitment Manager for Google Cloud, AWS, and Azure. These are negotiated spend commitments, rather than resource usage commitments; AWS agreements may be called Enterp…
- `list_contract_templates` — Manage contract templates for PartnerOps resellers (T1/T2). Lists contract templates owned by the authenticated tenant (from the bearer token). Requires ContractTemplatesAdmin, DoiT API access (platform:externalApi), and the channelops:c…
- `list_contracts` — List and manage tenant-scoped contracts as a T1/T2 PartnerOps caller. Lists the contracts held by the specified customer. Callable by a T1/T2 PartnerOps principal for its own tenant or any descendant tenant. Read access requires contract…
- `list_customer_group_users` — Manage explicit, named groups of downstream customers and the users scoped to them. Returns the users assigned to a customer group owned by the authenticated tenant, sorted by user ID. Requires the UsersManager permission.
- `list_customer_groups` — Manage explicit, named groups of downstream customers and the users scoped to them. Returns the ready customer groups owned by the authenticated tenant. Requires the UsersManager permission.
- `list_datahub_datasets` — Use this when the user wants to see available DataHub datasets. Returns a list of datasets with metadata. Do NOT use this for billing data (use run_query) or assets (use list_assets).
- `list_dimensions` — Use this when the user wants to see available dimensions for cost analysis queries. Returns id, label and type metadata only (no values), up to 200 dimensions per page, sorted by id. GKE dimensions are omitted. pageToken retrieves subseq…
- `list_folders` — Use this when the user wants to see their Cloud Analytics folders, which organize reports and allocations into a hierarchy. Returns a list of folders with their metadata. Do NOT use this for listing reports (use list_reports) or labels (…
- `list_gcp_billing_accounts` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns all GCP Billing Accounts accessible to the authenticated tenant. Use as the entry point to discover GCP bi…
- `list_gcp_billing_accounts_settings` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns one item per onboarded GCP Billing Account. Each item includes that billing account's recommendation and a…
- `list_gcp_planned_purchases` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns the laddering projections for the billing account, grouped by PS4C product line (service) and region. Each…
- `list_gcp_recommendations` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns commitment purchase recommendations for the billing account, filtered to the term preferred in each produc…
- `list_gcp_resource_cuds` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns a paginated list of resource-based (vCPU / memory) CUDs for the billing account. Optionally filter by CUD …
- `list_gcp_spend_cuds` — Evaluate current GCP commitments, plan and automate purchases, and optimize cloud costs with PerfectScale for Commitments. Returns a paginated list of spend-based CUDs for the billing account. Optionally filter by CUD state (status); omi…
- `list_geographic_access_countries` — Manage country-based access to tenants in your customer hierarchy. Returns the canonical ISO 3166-1 alpha-2 country catalogue used by geographic access policies.
- `list_geographic_access_custom_regions` — Manage country-based access to tenants in your customer hierarchy. Returns the ready custom regions owned by the authenticated tenant. Requires the UsersManager permission.
- `list_invoices` — Use this when the user wants to see their invoices, check billing history, or review payment records. Returns a list of invoices with amounts, dates, and status. Do NOT use this for cost analysis (use run_query) or budget tracking (use l…
- `list_labels` — Use this when the user wants to see their DoiT console labels for organizing reports, budgets, alerts, allocations, metrics and annotations. Returns label metadata; these are not cloud resource labels. Do NOT use this for annotations (us…
- `list_optimization_recommendations` — Use this when the user asks about optimization, recommendations, insights, savings opportunities, rightsizing, idle resources, security findings, or cost reduction suggestions. Also use this when the user asks 'what insights are availabl…
- `list_organizations` — Use this when the user wants to see the organizations in their DoiT account. Returns a list of organizations. Do NOT use this for listing users (use list_users) or platforms (use list_platforms).
- `list_platforms` — Use this when the user wants to see the support-ticket platform catalog. Returns platform IDs and display names for create_ticket; this catalog does not list connected cloud accounts. Do NOT use this for cloud incidents (use get_cloud_in…
- `list_products` — Use this when the user wants to see the support-ticket product catalog. Returns product IDs, display names, and platform IDs. create_ticket uses the product displayName and the platform ID. Customers do not see private products. This cat…
- `list_reports` — Use this when the user wants to see their saved Cloud Analytics reports or browse available reports. Returns pages of up to 40 reports with IDs and metadata, newest creation first. rowCount counts this page; pageToken retrieves the next …
- `list_roles` — Use this when the user wants to see available roles in their DoiT organization. Returns a list of roles with permissions. Do NOT use this for listing users (use list_users) or organizations (use list_organizations).
- `list_service_account_tokens` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns the service account's non-deleted API tokens in a single unpaginated items array, at most 10. Secret material is never returned here …
- `list_service_accounts` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Returns every service account owned by the authenticated customer in a single unpaginated items array, in no guaranteed order. Requires the s…
- `list_service_quotas` — Monitor cloud service quota usage across connected accounts and projects. Returns the latest service quota usage snapshots collected by DoiT for the authenticated customer. Results include only quotas retained by DoiT's monitoring collec…
- `list_shared_payer_account_mappings` — Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a shared payer to T3 end customers. Lists the AWS accounts under the reseller's linked shared payers, together with the end custo…
- `list_shared_payer_management_accounts` — Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a shared payer to T3 end customers. Lists the reseller's linked shared-payer management (payer) accounts that have completed onbo…
- `list_shared_payers` — Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a shared payer to T3 end customers. Lists every shared payer linked to the reseller, including ones still mid-onboarding, with pe…
- `list_themes` — Use this when the user wants to see the custom color themes defined for their account, which control the colors applied to Cloud Analytics reports. Returns a list of themes with their metadata. Do NOT use this for listing reports (use li…
- `list_ticket_comments` — Returns all comments on a support ticket. For customers, only public comments are returned. For DoiT employees, both public and private comments are returned.
- `list_ticket_tags` — Create and manage support tickets with DoiT. Returns the tags currently set on a support request. DoiT employee (doer) callers receive the full tag set verbatim, including internal namespaces (e.g. tier/*, synapse_*). Customer callers re…
- `list_tickets` — Use this when the user wants to view their support tickets, check ticket status, or review open issues. Returns tickets with status, severity, and platform. Customers see their own tickets; organization tickets are visible when ticket sh…
- `list_users` — Use this when the user wants to see users in their DoiT organization or check who has access. Includes active users and pending invitations. Returns roleId values, which resolve to role details in list_roles. Do NOT use this for listing …
- `list_widgets` — Beta. Read precomputed current-month cloud spend and forecast metrics. Widget results are refreshed in the background; reading a widget returns the latest cached result and never starts a synchronous refresh. Use the list operation to di…
- `search_cloud_diagrams` — Use this when the user wants to search their cloud infrastructure diagrams and components by name or property. Returns matching diagram layers (scheme), components, and components matched by property value (prop). ss_id scopes only compo…
- `test_run_cloudflow_flow` — Manage CloudFlow. Runs a flow once as a test, and accepts an unpublished (draft) flow — unlike actions/trigger, which requires the flow to be published. Use this to verify a newly authored or edited flow before publishing it. Execution i…
- `validate_user` — Use this when the user asks to verify their account connection or check who they are logged in as. Returns the authenticated user's email and the primary domain of the customer the session is scoped to. Authentication is already establis…
- `verify_signup_request` — Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothing until the organization's admin verifies the request. Agen…
- `accept_budget_suggestion` — AI-generated budget recommendations you can accept (link to a budget you created) or dismiss. Marks the suggestion as accepted and links it to an existing budget. Create the budget first via POST /analytics/v1/budgets, then pass its id a…
- `add_ticket_tags` — Create and manage support tickets with DoiT. Adds one or more tags to an existing support request. The operation is surgical — only the tags listed in the request are added; existing tags on the ticket are preserved. Re-adding a tag that…
- `assign_contract_template` — Manage contract templates for PartnerOps resellers (T1/T2). Applies a contract template owned by the authenticated tenant (from the bearer token) to child customers, creating a draft contract for each. Drafts have no billing effect until…
- `assign_customer_group_user` — Manage explicit, named groups of downstream customers and the users scoped to them. Assigns a user to a customer group owned by the authenticated tenant. Requires the UsersManager permission.
- `assign_objects_to_label` — Use this when the user wants to assign or unassign DoiT console objects (reports, budgets, alerts, allocations, metrics or annotations) to a custom console label. Preset labels cannot be assigned. Requires edit permission on every object…
- `create_account_role` — Manage cloud provider connections and check feature availability for connected accounts. Creates or updates a CloudConnect document for an AWS account. Unlike the CloudFormation variant, this endpoint does not update Firestore channel do…
- `create_alert` — Use this when the user wants to set up a new cost alert with thresholds and notification settings. Changes apply immediately. Do NOT use this for creating budgets (use create_budget) or viewing existing alerts (use list_alerts).
- `create_allocation` — Use this when the user wants to create a new cost allocation rule. Changes apply immediately. Do NOT use this for viewing existing allocations (use list_allocations) or labels (use create_label).
- `create_annotation` — Use this when the user wants to add a new annotation to mark a specific date or event in cost data. Changes apply immediately. Do NOT use this for creating labels (use create_label) or alerts (use create_alert).
- `create_asset` — Manage cloud resources or services in your cloud environment. Creates a new asset.
- `create_budget` — Use this when the user wants to create a new cloud budget with spending limits and alert thresholds. Requires name, currency, type, startPeriod, and exactly one of scope/scopes. Requires amount unless usePrevSpend is true, endPeriod for …
- `create_cloudflow_connection` — Use this when the user wants to create a new CloudFlow cloud provider connection (a GCP or AWS account connected for automation). Exactly one of gcpConfig or awsConfig must be supplied. Changes apply immediately. Do NOT use this to updat…
- `create_custom_theme` — Creates a new custom color theme. Requires Cloud Analytics Admin permission.
- `create_customer_group` — Manage explicit, named groups of downstream customers and the users scoped to them. Creates a customer group owned by the authenticated tenant. Requires the UsersManager permission.
- `create_datahub_dataset` — Use this when the user wants to create a new DataHub dataset. Changes apply immediately. Do NOT use this for viewing datasets (use list_datahub_datasets) or sending events (use send_datahub_events).
- `create_folder` — Use this when the user wants to create a new Cloud Analytics folder to organize reports and allocations. A duplicate sibling name or invalid parent is rejected. Changes apply immediately. Do NOT use this for creating reports (use create_…
- `create_geographic_access_custom_region` — Manage country-based access to tenants in your customer hierarchy. Creates a custom region owned by the authenticated tenant. The tenant must be a customer-hierarchy root. Requires the UsersManager permission.
- `create_label` — Use this when the user wants to create a new DoiT console label for organizing analytics objects. Names must be unique within the customer. Requires Cloud Analytics Admin. Changes apply immediately. Do NOT use this for viewing existing l…
- `create_report` — Use this when the user wants to save a new Cloud Analytics report with a specific configuration. Creates a new custom report immediately without replacing existing reports. Omitted config fields take API defaults: basic cost, last 7 days…
- `create_role` — Manage user permissions and access levels in your organization. Creates a custom role in the authenticated customer with the given permission IDs. Permission IDs are the permissions values returned by GET /iam/v1/roles. A service account…
- `create_service_account` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Creates a service account owned by the authenticated customer. It cannot authenticate anything until it has an API token; mint one with the a…
- `create_service_account_token` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Mints an API token for the service account and returns its accessToken once. The token inherits the service account's permissions as they sta…
- `create_signup_request` — Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothing until the organization's admin verifies the request. Agen…
- `create_signup_session` — Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothing until the organization's admin verifies the request. Agen…
- `create_ticket` — Use this when the user wants to create a new support ticket. The ticket is opened with DoiT support immediately. Do NOT use this for viewing existing tickets (use list_tickets) or cloud incidents (use get_cloud_incidents).
- `create_ticket_comment` — Adds a comment to an existing support ticket. For customers, comments are always public. For DoiT employees, comments can be marked as private (internal notes) by setting the private field to true.
- `datahub_import_provider_records` — Ingest third-party cost, usage, and metric-based data for analysis. Sends provider-native records as JSON instead of a CSV file. The records use the same columns as the template's CSV (currently anthropic-spend-report@1 only) and are val…
- `export_cloud_diagram_json` — Cloud Diagrams visualize your cloud infrastructure and resource relationships. Exports the full content of a diagram layer as a structured JSON document, including all components and export metadata.
- `export_cloudflow_flow` — Manage CloudFlow. Serializes the flow — plus every flow it references through subflow nodes — into a tenant-neutral, credential-free JSON bundle that can be imported into any tenant with the import operation. Tenant-scoped references (co…
- `export_datahub_dataset_records` — Ingest third-party cost, usage, and metric-based data for analysis. Returns one page of the live records of a DataHub dataset, as CSV (default) or as newline-delimited JSON in the same shape as the /datahub/v1/events payload. A time wind…
- `import_cloudflow_flow` — Manage CloudFlow. Creates every flow of a previously exported bundle in the authenticated tenant. Imports are create-only: each call creates new draft flows with new IDs — nothing is published and no schedule is activated until the targe…
- `invite_user` — Use this when the user wants to invite a new person to the organization. The invitation email is sent immediately. Omitted roleId defaults to Support User. The email domain must be permitted by the customer's invitation policy; existing …
- `patch_anomaly` — Monitor cost spikes in your cloud environment. Updates the review status of the anomaly identified by {id}, the same identifier getAnomaly accepts. Mirrors the review workflow available in the console: set reviewStatus, and when resolvin…
- `post_insight_resource_results` — Manage cloud insights representing recommendations and findings for cloud resources. Replaces all resource results for the specified insight. Any existing unresolved resource results not present in the new set will be removed. The respon…
- `post_insight_result` — Use this when the user wants to create a new custom insight or update an existing one's metadata (title, description, categories, status, remediation links). Only insights owned by the 'public-api' source can be managed (the default sour…
- `post_insight_results` — Manage cloud insights representing recommendations and findings for cloud resources. Creates or updates multiple insights in a single batch request. Each insight in the batch includes its metadata and resource results inline. For granula…
- `reassign_shared_payer_account` — Link and manage shared-payer account mappings for PartnerOps resellers (T2), reassigning AWS accounts under a shared payer to T3 end customers. Reassigns one AWS account under a linked shared payer - a member account or the payer's own m…
- `resend_invite` — Manage users who have access to the DoiT platform. Resets the invite expiry to 48 hours from now, invalidates the previous invite token (so old email links stop working), and triggers a fresh invitation email. Works on invites in any sta…
- `send_datahub_events` — Use this when the user wants to send DataHub events for ingestion (1–50,000 events per call). Each event requires a provider name and an RFC 3339 timestamp, and can optionally include dimensions and metrics. The API validates the entire …
- `set_active_theme` — Use this when the user wants to change the authenticated user’s active Cloud Analytics color theme. Accepts a custom theme ID or supported preset ID or the sentinel "default" to revert to the built-in default. Changes apply immediately. …
- `unassign_customer_group_user` — Manage explicit, named groups of downstream customers and the users scoped to them. Unassigns a user from a customer group owned by the authenticated tenant. Requires the UsersManager permission.
- `update_alert` — Use this when the user wants to modify an existing cost alert. Supports partial updates, including name-only, recipients-only, or individual config fields. Omitted fields are preserved; scopes: [] clears scopes. Changes apply immediately…
- `update_allocation` — Use this when the user wants to modify an existing cost allocation. Omitted fields are preserved. Use rule for an existing single allocation and rules for an existing group; the type cannot change. A supplied rules list replaces the enti…
- `update_annotation` — Use this when the user wants to modify an existing annotation. Nonempty content is required on every update. Omitted or null timestamp/reports/labels remain unchanged; reports and labels replace their lists, and [] clears them. Changes a…
- `update_aws_feature` — Manage cloud provider connections and check feature availability for connected accounts. Updates an AWS feature for an existing CloudConnect account. Unlike the CloudFormation variant, this endpoint does not update Firestore channel docu…
- `update_budget` — Use this when the user wants to modify an existing budget. Supports partial updates; omitted fields retain their current values. Setting type to fixed requires endPeriod; setting type to recurring requires timeInterval and forbids endPer…
- `update_cloudflow_connection` — Updates a CloudFlow connection immediately using connectionId and the last observed ETag (ifMatch). A stale ETag fails with 412. Other fields are optional; supplied gcpConfig/awsConfig and collaborators replace their stored values wholes…
- `update_customer` — Read and update your organization's general settings. Partially updates the general settings and contact info of the customer identified by {customerId}. {customerId} must match the customer resolved from the bearer token; a token scoped…
- `update_customer_geographic_access_scope` — Manage country-based access to tenants in your customer hierarchy. Atomically replaces the geographic scope for a target customer. The authenticated tenant must be the hierarchy root, and the target must be that root customer or one of i…
- `update_customer_group` — Manage explicit, named groups of downstream customers and the users scoped to them. Updates the name, customer membership, or both for a customer group owned by the authenticated tenant. Requires the UsersManager permission.
- `update_datahub_dataset` — Use this when the user wants to modify an existing DataHub dataset's description, displayName, or logoName. The dataset name identifies the dataset and cannot be changed. Omitted fields are kept; empty strings clear the supplied fields. …
- `update_folder` — Use this when the user wants to rename, re-describe, or move (reparent) an existing Cloud Analytics folder. Changes apply immediately. Auto-renaming on collision applies only when moving to another parent; a rename that collides with a s…
- `update_geographic_access_custom_region` — Manage country-based access to tenants in your customer hierarchy. Updates the name, country membership, or both for a custom region owned by the authenticated tenant. Requires the UsersManager permission.
- `update_insight_status` — Use this when the user wants to change the display status of an existing insight (e.g. mark it acknowledged, in progress, optimized, or dismissed). This endpoint is deprecated but remains the safe choice for status-only changes because i…
- `update_label` — Use this when the user wants to modify an existing custom DoiT console label. Requires Cloud Analytics Admin; preset labels cannot be edited. Supports partial updates; null leaves a field unchanged. Changes apply immediately. Do NOT use …
- `update_report` — Use this when the user wants to modify an existing saved Cloud Analytics report. Only custom reports the caller can edit are supported. Supports partial updates with array replacement and config reset semantics described on config. Omitt…
- `update_resource_permissions` — Use this when the user wants to change who a Cloud Analytics resource is shared with or update access levels. Replaces sharing settings with PUT for a specific alert, budget, custom report, or allocation. Requires resourceType, resourceI…
- `update_role` — Manage user permissions and access levels in your organization. Updates the name, description and/or permissions of a custom role. Only the fields present in the body change; permissions replaces the full list when present. Preset roles …
- `update_service_account` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Partially updates a service account with an application/merge-patch+json body (RFC 7396). Omitted or null fields stay unchanged; an explicit …
- `update_service_account_token` — Manage non-human identities whose API tokens call the DoiT API with a fixed set of permissions. Moves the token between active and disabled by setting state. Disabling takes effect immediately: the token stops authenticating until it is …
- `update_theme` — Use this when the user wants to modify an existing custom color theme — rename it, change its primary color, or update its color palette. Accepts either the theme ID or a partial name match across all custom themes; ambiguous matches ret…
- `update_ticket` — Create and manage support tickets with DoiT. Partially updates a support request. Supports setting the request status and/or assignee. DoiT employees may set any of open, pending, hold, or solved and may set the assignee; customers may s…
- `update_user` — Use this when the user wants to update a user's information such as name, job function, phone, language, or role. Changes apply immediately. Do NOT use this for inviting new users (use invite_user) or listing users (use list_users).
- `update_user_geographic_access_scope` — Manage country-based access to tenants in your customer hierarchy. Atomically replaces the geographic scope assigned to a user who belongs to the target customer. The authenticated tenant must be the hierarchy root, and the target must b…

## Related servers

- UnClick (1662 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Apibase (1384 tools) — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase.md
- Delx Mcp A2a (1068 tools) — https://policylayer.com/tools/io-github-davidmosiah-delx-mcp-a2a.md
- MCP Framework Personal (912 tools) — https://policylayer.com/tools/inggerman-mcps.md
- Hermoso (896 tools) — https://policylayer.com/tools/hermoso.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Eda Agent (777 tools) — https://policylayer.com/tools/eda-agent.md
- Delx MCP Server (740 tools) — https://policylayer.com/tools/io-github-davidmosiah-delx-mcp-server.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=doit · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/doit
