# Access reviews MCP tools

This page documents **27 tools** in the access reviews group. Return to the [complete MCP tool reference](/docs/developers/api/mcp/tools) to browse another group.

Select a tool to inspect its schemas and behavior. Schema links open the exact definition in GitHub.

### `listAccessReviewCampaigns` — List Access Review Campaigns

List access review campaigns for an organization.

- **Input:** [`ListAccessReviewCampaignsInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10136-L10152)
- **Output:** [`ListAccessReviewCampaignsOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10154-L10165)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L18875–L18886 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18875-L18886)

### `listAccessEntries` — List Access Entries

List access entries for a campaign with optional filters (decision, flag, is_admin, active, auth_method, account_type).

- **Input:** [`ListAccessEntriesInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10167-L10205)
- **Output:** [`ListAccessEntriesOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10207-L10218)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L18887–L18898 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18887-L18898)

### `getAccessReviewStatistics` — Get Access Review Statistics

Get statistics for an access review campaign including counts by decision and flag.

- **Input:** [`GetAccessReviewStatisticsInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10220-L10227)
- **Output:** [`GetAccessReviewStatisticsOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10229-L10235)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L18899–L18910 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18899-L18910)

### `recordAccessReviewEntryDecision` — Record Access Review Entry Decision

Record a decision on an access entry (APPROVED, REVOKE, DEFER, or ESCALATE). Non-APPROVED decisions require a decision_note.

- **Input:** [`RecordAccessReviewEntryDecisionMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10237-L10251)
- **Output:** [`RecordAccessReviewEntryDecisionMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10253-L10259)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L18911–L18922 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18911-L18922)

### `recordAccessReviewEntryDecisions` — Record Access Review Entry Decisions

Record decisions on multiple access entries in a single batch. Non-APPROVED decisions require a decision_note.

- **Input:** [`RecordAccessReviewEntryDecisionsMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10261-L10282)
- **Output:** [`RecordAccessReviewEntryDecisionsMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10284-L10292)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L18923–L18934 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18923-L18934)

### `flagAccessReviewEntry` — Flag Access Review Entry

Flag an access entry with one or more flags during review (ORPHANED, INACTIVE, EXCESSIVE, ROLE_MISMATCH, NEW, etc.). Optionally provide reasons.

- **Input:** [`FlagAccessReviewEntryMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10294-L10312)
- **Output:** [`FlagAccessReviewEntryMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10314-L10320)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L18935–L18946 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18935-L18946)

### `closeAccessReviewCampaign` — Close Access Review Campaign

Close an access review campaign. All entries must have been decided (no PENDING entries).

- **Input:** [`CloseAccessReviewCampaignMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10322-L10329)
- **Output:** [`CloseAccessReviewCampaignMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10331-L10337)
- **Behavior:** Writes data · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L18947–L18958 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18947-L18958)

### `listAccessReviewSources` — List Access Review Sources

List access sources for an organization.

- **Input:** [`ListAccessReviewSourcesInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10400-L10416)
- **Output:** [`ListAccessReviewSourcesOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10418-L10429)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L18959–L18970 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18959-L18970)

### `createAccessReviewSource` — Create Access Review Source

Create a new access source for an organization.

- **Input:** [`CreateAccessReviewSourceMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10431-L10451)
- **Output:** [`CreateAccessReviewSourceMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10453-L10466)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L18971–L18982 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18971-L18982)

### `updateAccessReviewSource` — Update Access Review Source

Update an existing access source.

- **Input:** [`UpdateAccessReviewSourceMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10468-L10490)
- **Output:** [`UpdateAccessReviewSourceMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10492-L10498)
- **Behavior:** Writes data · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L18983–L18994 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18983-L18994)

### `deleteAccessReviewSource` — Delete Access Review Source

Delete an access source.

- **Input:** [`DeleteAccessReviewSourceMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10500-L10507)
- **Output:** [`DeleteAccessReviewSourceMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10509-L10516)
- **Behavior:** Writes data · Destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L18995–L19006 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L18995-L19006)

### `awsConnectorSetup` — AWS Connector Setup

Return issuer, subject, audience and deploy artifacts for connecting an AWS account.

- **Input:** [`AWSConnectorSetupMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10588-L10595)
- **Output:** [`AWSConnectorSetupMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10597-L10603)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19007–L19018 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19007-L19018)

### `gcpConnectorSetup` — GCP Connector Setup

Return issuer, subject, audience template and deploy artifacts for connecting a GCP project.

- **Input:** [`GCPConnectorSetupMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10630-L10637)
- **Output:** [`GCPConnectorSetupMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10639-L10645)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19019–L19030 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19019-L19030)

### `azureConnectorSetup` — Azure Connector Setup

Return issuer, subject, audience and deploy artifacts for connecting an Azure subscription.

- **Input:** [`AzureConnectorSetupMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10682-L10689)
- **Output:** [`AzureConnectorSetupMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10691-L10697)
- **Behavior:** Read only · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19031–L19042 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19031-L19042)

### `createWorkloadIdentityConnector` — Create Workload Identity Connector

Create a workload-identity connector (AWS, GCP, or Azure) and report whether the audit identity can be assumed.

- **Input:** [`CreateWorkloadIdentityConnectorMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10708-L10768)
- **Output:** [`CreateWorkloadIdentityConnectorMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10770-L10776)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Open world
- **Source:** [specification.yaml · L19043–L19054 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19043-L19054)

### `listConnectors` — List Connectors

List connectors for an organization.

- **Input:** [`ListConnectorsMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10819-L10826)
- **Output:** [`ListConnectorsMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10828-L10836)
- **Behavior:** Read only · Non-destructive · Idempotent · Open world
- **Source:** [specification.yaml · L19055–L19066 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19055-L19066)

### `getConnector` — Get Connector

Get a connector by ID.

- **Input:** [`GetConnectorMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10838-L10845)
- **Output:** [`GetConnectorMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10847-L10853)
- **Behavior:** Read only · Non-destructive · Idempotent · Open world
- **Source:** [specification.yaml · L19067–L19078 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19067-L19078)

### `createOrganizationConnector` — Create Organization Connector

Create an organization-scoped workload-identity connector and list discovered accounts.

- **Input:** [`CreateOrganizationConnectorMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10855-L10916)
- **Output:** [`CreateOrganizationConnectorMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10918-L10929)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Open world
- **Source:** [specification.yaml · L19079–L19090 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19079-L19090)

### `discoverConnectorAccounts` — Discover Connector Accounts

List vendor accounts a connector can enable.

- **Input:** [`DiscoverConnectorAccountsMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10931-L10937)
- **Output:** [`DiscoverConnectorAccountsMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10939-L10947)
- **Behavior:** Read only · Non-destructive · Idempotent · Open world
- **Source:** [specification.yaml · L19091–L19102 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19091-L19102)

### `enableConnectorAccounts` — Enable Connector Accounts

Enable vendor accounts on a connector without creating an access source.

- **Input:** [`EnableConnectorAccountsMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10961-L10972)
- **Output:** [`EnableConnectorAccountsMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10974-L10982)
- **Behavior:** Writes data · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19103–L19114 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19103-L19114)

### `createAccessReviewCampaign` — Create Access Review Campaign

Create a new access review campaign for an organization.

- **Input:** [`CreateAccessReviewCampaignMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L10984-L11003)
- **Output:** [`CreateAccessReviewCampaignMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11005-L11011)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L19115–L19126 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19115-L19126)

### `updateAccessReviewCampaign` — Update Access Review Campaign

Update an existing access review campaign.

- **Input:** [`UpdateAccessReviewCampaignMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11013-L11026)
- **Output:** [`UpdateAccessReviewCampaignMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11027-L11033)
- **Behavior:** Writes data · Non-destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19127–L19138 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19127-L19138)

### `deleteAccessReviewCampaign` — Delete Access Review Campaign

Delete an access review campaign.

- **Input:** [`DeleteAccessReviewCampaignMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11035-L11042)
- **Output:** [`DeleteAccessReviewCampaignMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11044-L11051)
- **Behavior:** Writes data · Destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19139–L19150 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19139-L19150)

### `startAccessReviewCampaign` — Start Access Review Campaign

Start an access review campaign. Triggers data fetching from all configured scope sources.

- **Input:** [`StartAccessReviewCampaignMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11053-L11060)
- **Output:** [`StartAccessReviewCampaignMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11062-L11068)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L19151–L19162 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19151-L19162)

### `cancelAccessReviewCampaign` — Cancel Access Review Campaign

Cancel an in-progress access review campaign.

- **Input:** [`CancelAccessReviewCampaignMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11070-L11077)
- **Output:** [`CancelAccessReviewCampaignMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11079-L11085)
- **Behavior:** Writes data · Destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19163–L19174 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19163-L19174)

### `addAccessReviewCampaignSource` — Add Access Review Campaign Source

Add an access source to an access review campaign's scope.

- **Input:** [`AddAccessReviewCampaignSourceMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11087-L11098)
- **Output:** [`AddAccessReviewCampaignSourceMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11100-L11106)
- **Behavior:** Writes data · Non-destructive · Non-idempotent · Closed world
- **Source:** [specification.yaml · L19175–L19186 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19175-L19186)

### `removeAccessReviewCampaignSource` — Remove Access Review Campaign Source

Remove an access source from an access review campaign's scope.

- **Input:** [`RemoveAccessReviewCampaignSourceMCPInput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11108-L11119)
- **Output:** [`RemoveAccessReviewCampaignSourceMCPOutput`](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L11121-L11127)
- **Behavior:** Writes data · Destructive · Idempotent · Closed world
- **Source:** [specification.yaml · L19187–L19198 ↗](https://github.com/getprobo/probo/blob/main/pkg/server/api/mcp/v1/specification.yaml#L19187-L19198)
