# list_optimization_recommendations

Use this when the user asks about optimization, recommendations, insights, savings opportunities, rightsizing, idle resources, security findings, or cost reduction suggestions. Also use this when the user asks 'what insights are available?' or 'show me insights'. This is the primary tool for 'what can I optimize?', 'how can I save money?', and 'what insights do I have?' questions. Returns insights ordered within each page by estimated daily savings, not priority. All statuses are included unless filtered, including dismissed. easyWin is derived from easyWinDescription when present, otherwise null. Follow pageToken for more results. Do NOT use this for cost anomalies/spikes (use get_anomalies) or budget tracking (use list_budgets).

Agent View of the PolicyLayer registry record for `list_optimization_recommendations`. HTML page: https://policylayer.com/tools/doit/list-optimization-recommendations

## Facts

- Tool: `list_optimization_recommendations`
- Server: Doit (`@doitintl/doit-mcp-server`) — https://policylayer.com/tools/doit.md
- Install: `npx -y @doitintl/doit-mcp-server`
- Homepage: https://www.npmjs.com/package/@doitintl/doit-mcp-server
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 10
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `page` | integer | no | Deprecated: only 0 (first page) is accepted. Use pageToken for continuation. |
| `easyWin` | boolean | no | True selects easy wins; false selects only non-easy-wins; omit for both. |
| `category` | object | no | Filter by one category; a legacy one-element array is accepted. OperationalExcellence/Operational excellence and PerformanceEfficiency/Performance efficiency ar |
| `pageSize` | integer | no | Deprecated alias for maxResults (default 20, max 100); maxResults takes precedence. |
| `priority` | array | no | Filter by priority levels. Possible values: Low, Medium, High. |
| `provider` | string | no | Filter by cloud provider (sent as cloudProvider to the API, e.g. aws, gcp, azure). |
| `pageToken` | string | no | Non-empty opaque cursor from the previous response. Omit for the first page. |
| `maxResults` | integer | no | Results per page, 1–500. Overrides pageSize; defaults to 20 for compatibility. |
| `searchTerm` | string | no | Case-insensitive substring search of insight titles only. |
| `displayStatus` | array | no | Filter by display status. Omitted means all statuses, including dismissed. Possible values: actionable, acknowledged, in progress, optimized, dismissed. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "list_optimization_recommendations",
    "arguments": {}
  }
}
```

## Why list_optimization_recommendations is rated Low

Even though list_optimization_recommendations only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.

Risk signals: High parameter count (10 properties)

## Use case

AI agents call list_optimization_recommendations to retrieve information from Doit without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Doit:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "list_optimization_recommendations": {}
  }
}
```

## Other tools on Doit (237)

- `cancel_async_operation` — Destructive — https://policylayer.com/tools/doit/cancel-async-operation.md
- `cancel_invite` — Destructive — https://policylayer.com/tools/doit/cancel-invite.md
- `confirm_action` — Destructive — https://policylayer.com/tools/doit/confirm-action.md
- `delete_account_role` — Destructive — https://policylayer.com/tools/doit/delete-account-role.md
- `delete_alert` — Destructive — https://policylayer.com/tools/doit/delete-alert.md
- `delete_allocation` — Destructive — https://policylayer.com/tools/doit/delete-allocation.md
- `delete_annotation` — Destructive — https://policylayer.com/tools/doit/delete-annotation.md
- `delete_ava_conversation` — Destructive — https://policylayer.com/tools/doit/delete-ava-conversation.md
- `delete_budget` — Destructive — https://policylayer.com/tools/doit/delete-budget.md
- `delete_cloudflow_connection` — Destructive — https://policylayer.com/tools/doit/delete-cloudflow-connection.md
- `delete_custom_theme` — Destructive — https://policylayer.com/tools/doit/delete-custom-theme.md
- `delete_customer_geographic_access_scope` — Destructive — https://policylayer.com/tools/doit/delete-customer-geographic-access-scope.md
- `delete_customer_group` — Destructive — https://policylayer.com/tools/doit/delete-customer-group.md
- `delete_datahub_dataset` — Destructive — https://policylayer.com/tools/doit/delete-datahub-dataset.md
- `delete_datahub_datasets` — Destructive — https://policylayer.com/tools/doit/delete-datahub-datasets.md
- `delete_datahub_events_by_filter` — Destructive — https://policylayer.com/tools/doit/delete-datahub-events-by-filter.md
- `delete_folder` — Destructive — https://policylayer.com/tools/doit/delete-folder.md
- `delete_geographic_access_custom_region` — Destructive — https://policylayer.com/tools/doit/delete-geographic-access-custom-region.md
- `delete_insight_result` — Destructive — https://policylayer.com/tools/doit/delete-insight-result.md
- `delete_insight_results` — Destructive — https://policylayer.com/tools/doit/delete-insight-results.md
- `delete_label` — Destructive — https://policylayer.com/tools/doit/delete-label.md
- `delete_report` — Destructive — https://policylayer.com/tools/doit/delete-report.md
- `delete_role` — Destructive — https://policylayer.com/tools/doit/delete-role.md
- `delete_service_account` — Destructive — https://policylayer.com/tools/doit/delete-service-account.md
- `delete_service_account_token` — Destructive — https://policylayer.com/tools/doit/delete-service-account-token.md
- `delete_user` — Destructive — https://policylayer.com/tools/doit/delete-user.md
- `delete_user_geographic_access_scope` — Destructive — https://policylayer.com/tools/doit/delete-user-geographic-access-scope.md
- `id_of_asset` — Destructive — https://policylayer.com/tools/doit/id-of-asset.md
- `remove_ticket_tags` — Destructive — https://policylayer.com/tools/doit/remove-ticket-tags.md
- `async_run_inline` — Execute — https://policylayer.com/tools/doit/async-run-inline.md
- …and 207 more: https://policylayer.com/tools/doit.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=doit · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/doit
