accessoracle
AccessOracle - 10 access control tools: IAM, PAM, recertification, segregation of duties.
使うべきか
品質と安全性
検出事項(2)
- LOWaccess_gap_analysis 内
- LOWhealth_check 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"accessoracle": {
"url": "https://tooloracle.io/access/mcp/"
}
}
}リモートエンドポイント
https://tooloracle.io/access/mcp/streamable-httpできること
ツール一覧
ツール(10)
⚪register_account(account_id, username, account_type, system, owner, ...)
Register a privileged/service/shared account for IAM tracking.
入力スキーマ
{
"type": "object",
"properties": {
"account_id": {
"type": "string"
},
"username": {
"type": "string"
},
"account_type": {
"type": "string",
"enum": [
"privileged",
"service",
"shared",
"standard",
"break_glass"
]
},
"system": {
"type": "string"
},
"owner": {
"type": "string"
},
"department": {
"type": "string"
},
"mfa_method": {
"type": "string",
"enum": [
"totp",
"fido2",
"smartcard",
"push",
"sms",
"none"
]
},
"mfa_enabled": {
"type": "boolean"
},
"is_shared": {
"type": "boolean"
},
"criticality": {
"type": "string",
"enum": [
"critical",
"important",
"standard"
]
},
"remote_access": {
"type": "boolean"
},
"cif_access": {
"type": "boolean"
},
"notes": {
"type": "string"
}
},
"required": [
"username",
"account_type"
],
"additionalProperties": false
}🟢list_accounts(account_type, system, no_mfa)
List accounts with filters.
入力スキーマ
{
"type": "object",
"properties": {
"account_type": {
"type": "string"
},
"system": {
"type": "string"
},
"no_mfa": {
"type": "boolean"
}
},
"additionalProperties": false
}🟢mfa_compliance
Check MFA coverage against DORA Art. 9(4)(d) requirements.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟡access_review(add, account_id, reviewer, decision, review_date, ...)
Track access recertification reviews. Set add=true to log a review.
入力スキーマ
{
"type": "object",
"properties": {
"add": {
"type": "boolean"
},
"account_id": {
"type": "string"
},
"reviewer": {
"type": "string"
},
"decision": {
"type": "string",
"enum": [
"confirmed",
"revoked",
"modified"
]
},
"review_date": {
"type": "string"
},
"overdue_days": {
"type": "integer"
},
"notes": {
"type": "string"
}
},
"additionalProperties": false
}⚪sod_matrix
Detect Segregation of Duties conflicts across accounts.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪privileged_audit
Privileged account audit — MFA, shared, review status.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟡jml_process(log_event, event_type, username, date, actions_taken, ...)
Joiner/Mover/Leaver process tracking. Set log_event=true to log.
入力スキーマ
{
"type": "object",
"properties": {
"log_event": {
"type": "boolean"
},
"event_type": {
"type": "string",
"enum": [
"joiner",
"mover",
"leaver"
]
},
"username": {
"type": "string"
},
"date": {
"type": "string"
},
"actions_taken": {
"type": "string"
},
"verified_by": {
"type": "string"
}
},
"additionalProperties": false
}🟡break_glass_log(log, account_id, reason, used_by, approved_by, ...)
Emergency access logging. Set log=true to record usage.
入力スキーマ
{
"type": "object",
"properties": {
"log": {
"type": "boolean"
},
"account_id": {
"type": "string"
},
"reason": {
"type": "string"
},
"used_by": {
"type": "string"
},
"approved_by": {
"type": "string"
},
"duration_minutes": {
"type": "integer"
}
},
"additionalProperties": false
}⚪access_gap_analysis
Gap analysis against RTS Art. 21 requirements.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢health_check
Server status.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false
}コミュニティ
エビデンス