post_insight_result
Use this when the user wants to create a new custom insight or update an existing one's metadata (title, description, categories, status, remediation links). Only insights owned by the 'public-api' source can be managed (the default source). Requires key, title, shortDescription, cloudProvider an...
This record as markdown: /tools/doit/post-insight-result.md
What post_insight_result does on Doit
AI agents use post_insight_result to create or update resources in Doit, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Doit environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
key | string | Yes | A unique key identifying the insight within the source. Used as both the path key and body key. |
title | string | Yes | The display title of the insight. |
source | string | — | The source that owns the insight. Only 'public-api' insights can be managed via this endpoint; defaults to public-api. |
status | string | — | The display status of the insight. |
reportUrl | string | — | URL to an external report related to this insight. |
categories | array | Yes | One or more categories this insight belongs to. Possible values: FinOps, Security. |
cloudProvider | string | Yes | The cloud provider associated with the insight (e.g. 'aws', 'gcp', 'azure'). |
dismissalDetails | object | — | Details for why the insight was dismissed (relevant when status is 'dismissed'). |
shortDescription | string | Yes | A brief summary of the insight. |
easyWinDescription | string | — | A description of why this insight is considered an easy win. |
cloudFlowTemplateId | string | — | ID of a CloudFlow template that can automate the remediation of this insight. |
detailedDescriptionMdx | string | — | A detailed description of the insight in MDX format. |
Parameters from the server's own tool schema.
Why post_insight_result is rated Medium
An AI agent can call post_insight_result faster than any human can review: one bad instruction and it creates or modifies resources in Doit by the hundred, each call as confident as the last.
Risk signalsHigh parameter count (14 properties) · Bulk/mass operation — affects multiple targets
Attacks that exploit this kind of access
The rule that runs post_insight_result safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Doit, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For post_insight_result, this is the rule to start with:
post_insight_result stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Doit, apply this rule, and every post_insight_result call is checked against it from then on.
Questions about post_insight_result
Use this when the user wants to create a new custom insight or update an existing one's metadata (title, description, categories, status, remediation links). Only insights owned by the 'public-api' source can be managed (the default source). Requires key, title, shortDescription, cloudProvider and categories on every call. This replaces insight metadata: omitted optional fields such as detailedDescriptionMdx, reportUrl, easyWinDescription and cloudFlowTemplateId are cleared. Affected resources are managed separately (post_insight_resource_results). For a status-only change, use update_insight_status to preserve metadata despite that endpoint's deprecation. It is categorised as a Write tool in the Doit MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
post_insight_result accepts 12 parameters: key, title, source, status, reportUrl, categories, cloudProvider, dismissalDetails, shortDescription, easyWinDescription, cloudFlowTemplateId, detailedDescriptionMdx. Required: key, title, categories, cloudProvider, shortDescription. The full parameter table on this page comes from the server's own tool schema.
Register the Doit MCP server in PolicyLayer and add a rule for post_insight_result: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Doit. Nothing to install.
post_insight_result is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the post_insight_result rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for post_insight_result. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
post_insight_result is provided by the Doit MCP server (@doitintl/doit-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Doit, and thousands of servers like it.
This server
Across the catalogue