# get_cloud_incidents

Use this when the user wants to check for active cloud platform outages, service disruptions, or incidents from AWS or Google Cloud. Both active and archived incidents are included unless status is filtered. Do NOT use this for cost anomalies (use get_anomalies) or support tickets (use list_tickets).

Agent View of the PolicyLayer registry record for `get_cloud_incidents`. HTML page: https://policylayer.com/tools/doit/get-cloud-incidents

## Facts

- Tool: `get_cloud_incidents`
- Server: Doit (`@doitintl/doit-mcp-server`) — https://policylayer.com/tools/doit.md
- Install: `npx -y @doitintl/doit-mcp-server`
- Homepage: https://www.npmjs.com/package/@doitintl/doit-mcp-server
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 3
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `filter` | string | no | Exact filters in format key:value\|key:value. Keys: platform (amazon-web-services or google-cloud), status (active or archived), product. Different keys use AND; |
| `platform` | object | no | Platform constraint: amazon-web-services or google-cloud. Legacy google-cloud-project is normalized to google-cloud. If filter also contains platform, it must s |
| `pageToken` | string | no | Token for pagination, from a previous response; returns the next page of results. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_cloud_incidents",
    "arguments": {}
  }
}
```

## Why get_cloud_incidents is rated Low

Even though get_cloud_incidents only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.

## Use case

AI agents call get_cloud_incidents to retrieve information from Doit without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Doit:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "get_cloud_incidents": {}
  }
}
```

## Other tools on Doit (237)

- `cancel_async_operation` — Destructive — https://policylayer.com/tools/doit/cancel-async-operation.md
- `cancel_invite` — Destructive — https://policylayer.com/tools/doit/cancel-invite.md
- `confirm_action` — Destructive — https://policylayer.com/tools/doit/confirm-action.md
- `delete_account_role` — Destructive — https://policylayer.com/tools/doit/delete-account-role.md
- `delete_alert` — Destructive — https://policylayer.com/tools/doit/delete-alert.md
- `delete_allocation` — Destructive — https://policylayer.com/tools/doit/delete-allocation.md
- `delete_annotation` — Destructive — https://policylayer.com/tools/doit/delete-annotation.md
- `delete_ava_conversation` — Destructive — https://policylayer.com/tools/doit/delete-ava-conversation.md
- `delete_budget` — Destructive — https://policylayer.com/tools/doit/delete-budget.md
- `delete_cloudflow_connection` — Destructive — https://policylayer.com/tools/doit/delete-cloudflow-connection.md
- `delete_custom_theme` — Destructive — https://policylayer.com/tools/doit/delete-custom-theme.md
- `delete_customer_geographic_access_scope` — Destructive — https://policylayer.com/tools/doit/delete-customer-geographic-access-scope.md
- `delete_customer_group` — Destructive — https://policylayer.com/tools/doit/delete-customer-group.md
- `delete_datahub_dataset` — Destructive — https://policylayer.com/tools/doit/delete-datahub-dataset.md
- `delete_datahub_datasets` — Destructive — https://policylayer.com/tools/doit/delete-datahub-datasets.md
- `delete_datahub_events_by_filter` — Destructive — https://policylayer.com/tools/doit/delete-datahub-events-by-filter.md
- `delete_folder` — Destructive — https://policylayer.com/tools/doit/delete-folder.md
- `delete_geographic_access_custom_region` — Destructive — https://policylayer.com/tools/doit/delete-geographic-access-custom-region.md
- `delete_insight_result` — Destructive — https://policylayer.com/tools/doit/delete-insight-result.md
- `delete_insight_results` — Destructive — https://policylayer.com/tools/doit/delete-insight-results.md
- `delete_label` — Destructive — https://policylayer.com/tools/doit/delete-label.md
- `delete_report` — Destructive — https://policylayer.com/tools/doit/delete-report.md
- `delete_role` — Destructive — https://policylayer.com/tools/doit/delete-role.md
- `delete_service_account` — Destructive — https://policylayer.com/tools/doit/delete-service-account.md
- `delete_service_account_token` — Destructive — https://policylayer.com/tools/doit/delete-service-account-token.md
- `delete_user` — Destructive — https://policylayer.com/tools/doit/delete-user.md
- `delete_user_geographic_access_scope` — Destructive — https://policylayer.com/tools/doit/delete-user-geographic-access-scope.md
- `id_of_asset` — Destructive — https://policylayer.com/tools/doit/id-of-asset.md
- `remove_ticket_tags` — Destructive — https://policylayer.com/tools/doit/remove-ticket-tags.md
- `async_run_inline` — Execute — https://policylayer.com/tools/doit/async-run-inline.md
- …and 207 more: https://policylayer.com/tools/doit.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=doit · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/doit
