Cloudera · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Cloudera Service Iam API

80 actions 80 updates phrasing extends openapi/cloudera-iam-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Cloudera's API. It is a proposal applied on top of the contract, not a document Cloudera publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 80 · first 16 shown; the file carries all of them

$.info
$.paths['/iam/getUser'].post
$.paths['/iam/listUsers'].post
$.paths['/iam/createUser'].post
$.paths['/iam/updateUser'].post
$.paths['/iam/deleteUser'].post
$.paths['/iam/createUserAccessKey'].post
$.paths['/iam/createMachineUserAccessKey'].post
$.paths['/iam/deleteAccessKey'].post
$.paths['/iam/updateAccessKey'].post
$.paths['/iam/getAccessKey'].post
$.paths['/iam/listAccessKeys'].post
$.paths['/iam/listRoles'].post
$.paths['/iam/listResourceRoles'].post
$.paths['/iam/setAccountMessages'].post
$.paths['/iam/getAccountMessages'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Cloudera Service Iam API
  version: 1.0.0
extends: openapi/cloudera-iam-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 79
- target: $.paths['/iam/getUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Look up a CDP user's details
      effect: read
      questions:
      - How can I see the details of one user in my CDP account?
      - Which CDP user does my current access key belong to?
      instructions:
      - text: Show me the CDP user profile for {userId}.
        slots:
          userId: requestBody.userId
      - text: Tell me which CDP user my access key is authenticated as.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listUsers'].post
  update:
    x-apievangelist-phrasing:
      intent: List users in the CDP account
      effect: read
      questions:
      - Can I get a list of every human user in my Cloudera CDP account?
      - Is the CDP user listing paginated with a page size?
      instructions:
      - text: List all users in my CDP account.
      - text: List the CDP users {userIds}, {pageSize} per page.
        slots:
          userIds: requestBody.userIds
          pageSize: requestBody.pageSize
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/createUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a CDP user
      effect: write
      questions:
      - How do I add a new person as a user in CDP with their email and identity provider ID?
      - Can I put a new CDP user into groups at the moment I create them?
      instructions:
      - text: Create a CDP user with email {email} and identity provider user ID {identityProviderUserId}.
        slots:
          email: requestBody.email
          identityProviderUserId: requestBody.identityProviderUserId
      - text: Create CDP user {firstName} {lastName} ({email}, IdP ID {identityProviderUserId}) and add them to groups {groups}.
        slots:
          firstName: requestBody.firstName
          lastName: requestBody.lastName
          email: requestBody.email
          identityProviderUserId: requestBody.identityProviderUserId
          groups: requestBody.groups
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/updateUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Activate or deactivate a CDP user
      effect: write
      questions:
      - Can I deactivate a CDP user without deleting them?
      - What happens if I send a user update with no fields changed?
      instructions:
      - text: Deactivate CDP user {user} by setting active to {active}.
        slots:
          user: requestBody.user
          active: requestBody.active
      - text: Reactivate the CDP user {user}.
        slots:
          user: requestBody.user
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/deleteUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete a CDP user and their access
      effect: destructive
      questions:
      - What gets removed when I delete a human user from CDP?
      - Does deleting a CDP user also remove their access keys and group memberships?
      instructions:
      - text: Delete CDP user {userId} along with their access keys and role assignments.
        slots:
          userId: requestBody.userId
      - text: Permanently remove the person {userId} from my CDP account.
        slots:
          userId: requestBody.userId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/createUserAccessKey'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an API access key for a user
      effect: write
      questions:
      - How do I generate a CDP API access key for a human user?
      - Can I choose the key type when creating an access key for a user?
      instructions:
      - text: Create a new API access key for user {user}.
        slots:
          user: requestBody.user
      - text: Generate a {type} access key for CDP user {user}.
        slots:
          type: requestBody.type
          user: requestBody.user
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/createMachineUserAccessKey'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an access key for a machine user
      effect: write
      questions:
      - How do I give a CDP machine user an API key for automation?
      - Which key types can I pick when creating a machine user's access key?
      instructions:
      - text: Create an access key for machine user {machineUserName}.
        slots:
          machineUserName: requestBody.machineUserName
      - text: Generate a {type} access key for the service account {machineUserName}.
        slots:
          type: requestBody.type
          machineUserName: requestBody.machineUserName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/deleteAccessKey'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete an API access key
      effect: destructive
      questions:
      - How do I permanently delete a CDP access key that leaked?
      - Is deleting an access key different from just disabling it?
      instructions:
      - text: Delete access key {accessKeyId}.
        slots:
          accessKeyId: requestBody.accessKeyId
      - text: Permanently remove the CDP API key {accessKeyId}.
        slots:
          accessKeyId: requestBody.accessKeyId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/updateAccessKey'].post
  update:
    x-apievangelist-phrasing:
      intent: Enable or disable an access key
      effect: write
      questions:
      - Can I temporarily disable a CDP access key instead of deleting it?
      - How do I turn an inactive access key back on?
      instructions:
      - text: Set the status of access key {accessKeyId} to {status}.
        slots:
          accessKeyId: requestBody.accessKeyId
          status: requestBody.status
      - text: Disable access key {accessKeyId} for now.
        slots:
          accessKeyId: requestBody.accessKeyId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/getAccessKey'].post
  update:
    x-apievangelist-phrasing:
      intent: Look up an access key's details
      effect: read
      questions:
      - Which actor owns a given CDP access key and is it active?
      - Can I see details of the access key I'm calling the API with?
      instructions:
      - text: Show details for access key {accessKeyId}.
        slots:
          accessKeyId: requestBody.accessKeyId
      - text: Describe the access key I'm currently using.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listAccessKeys'].post
  update:
    x-apievangelist-phrasing:
      intent: List access keys in the account
      effect: read
      questions:
      - What API access keys exist across my CDP account?
      - Can I page through access keys a few at a time?
      instructions:
      - text: List all CDP access keys.
      - text: List access keys {accessKeyIds}.
        slots:
          accessKeyIds: requestBody.accessKeyIds
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listRoles'].post
  update:
    x-apievangelist-phrasing:
      intent: List the account-level roles available
      effect: read
      questions:
      - What account-wide roles can I grant in CDP?
      - Which policies do CDP roles carry?
      instructions:
      - text: List every account role available in CDP.
      - text: Show the roles named {roleNames}.
        slots:
          roleNames: requestBody.roleNames
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listResourceRoles'].post
  update:
    x-apievangelist-phrasing:
      intent: List available resource roles
      effect: read
      questions:
      - Which resource roles exist for granting rights over specific CDP resources?
      - Can I look up a resource role's CRN by name?
      instructions:
      - text: List all resource roles available in CDP.
      - text: Show the resource roles {resourceRoleNames}.
        slots:
          resourceRoleNames: requestBody.resourceRoleNames
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/setAccountMessages'].post
  update:
    x-apievangelist-phrasing:
      intent: Set the account's contact-your-admin message
      effect: write
      questions:
      - Can I customize the 'contact your administrator' message users see in CDP?
      - Where do I set the help text shown to users who lack access?
      instructions:
      - text: Set the contact-your-administrator message to {contactYourAdministratorMessage}.
        slots:
          contactYourAdministratorMessage: requestBody.contactYourAdministratorMessage
      - text: Update the account message users see when they need admin help to {contactYourAdministratorMessage}.
        slots:
          contactYourAdministratorMessage: requestBody.contactYourAdministratorMessage
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/getAccountMessages'].post
  update:
    x-apievangelist-phrasing:
      intent: Get the account's custom messages
      effect: read
      questions:
      - What admin contact message is currently configured for my CDP account?
      - Can I read back the custom account messages users see?
      instructions:
      - text: Show the current account messages.
      - text: Get the contact-your-administrator text set on my CDP account.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/assignUserRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Grant an account role to a user
      effect: write
      questions:
      - How do I give a human user an account-level role like PowerUser?
      - What happens if the user already has that role?
      instructions:
      - text: Assign role {role} to user {user}.
        slots:
          role: requestBody.role
          user: requestBody.user
      - text: Grant {user} the account role {role}.
        slots:
          user: requestBody.user
          role: requestBody.role
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/unassignUserRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove an account role from a user
      effect: destructive
      questions:
      - How can I take an account role away from a human user?
      - Will unassigning fail if the user doesn't have the role?
      instructions:
      - text: Unassign role {role} from user {user}.
        slots:
          role: requestBody.role
          user: requestBody.user
      - text: Revoke the account role {role} held by {user}.
        slots:
          role: requestBody.role
          user: requestBody.user
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/assignUserResourceRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Grant a user a role on a specific resource
      effect: write
      questions:
      - How do I give a user rights over a single environment rather than the whole account?
      - What CRNs do I need to grant a resource role to a person?
      instructions:
      - text: Assign resource role {resourceRoleCrn} on {resourceCrn} to user {user}.
        slots:
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
          user: requestBody.user
      - text: Give user {user} the {resourceRoleCrn} resource role over resource {resourceCrn}.
        slots:
          user: requestBody.user
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/unassignUserResourceRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a user's role on a specific resource
      effect: destructive
      questions:
      - How do I revoke a person's access to one specific CDP resource?
      - Does removing a user's resource role fail if it wasn't assigned?
      instructions:
      - text: Unassign resource role {resourceRoleCrn} on {resourceCrn} from user {user}.
        slots:
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
          user: requestBody.user
      - text: Revoke user {user}'s {resourceRoleCrn} rights over {resourceCrn}.
        slots:
          user: requestBody.user
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listUserAssignedRoles'].post
  update:
    x-apievangelist-phrasing:
      intent: List a user's account roles
      effect: read
      questions:
      - What account roles does a particular human user hold?
      - Which account roles do I have myself?
      instructions:
      - text: List the account roles assigned to user {user}.
        slots:
          user: requestBody.user
      - text: Show my own assigned account roles.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listUserAssignedResourceRoles'].post
  update:
    x-apievangelist-phrasing:
      intent: List a user's resource role assignments
      effect: read
      questions:
      - Which resources does a user have resource roles on?
      - Can I audit a person's per-resource permissions?
      instructions:
      - text: List the resource roles assigned to user {user}.
        slots:
          user: requestBody.user
      - text: Show my own resource role assignments.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/assignMachineUserRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Grant an account role to a machine user
      effect: write
      questions:
      - How do I give a service account (machine user) an account-level role?
      - Will it error if the machine user already has the role?
      instructions:
      - text: Assign role {role} to machine user {machineUserName}.
        slots:
          role: requestBody.role
          machineUserName: requestBody.machineUserName
      - text: Grant the service account {machineUserName} the account role {role}.
        slots:
          machineUserName: requestBody.machineUserName
          role: requestBody.role
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/unassignMachineUserRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove an account role from a machine user
      effect: destructive
      questions:
      - Can I strip an account role from a machine user?
      - What if the machine user doesn't actually hold the role I'm removing?
      instructions:
      - text: Unassign role {role} from machine user {machineUserName}.
        slots:
          role: requestBody.role
          machineUserName: requestBody.machineUserName
      - text: Revoke account role {role} from the service account {machineUserName}.
        slots:
          role: requestBody.role
          machineUserName: requestBody.machineUserName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/assignMachineUserResourceRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Grant a machine user a role on a resource
      effect: write
      questions:
      - How do I scope a machine user's permissions to a single CDP resource?
      - Which CRNs are required to give a service account a resource role?
      instructions:
      - text: Grant machine account {machineUserName} resource-scoped role {resourceRoleCrn} over {resourceCrn}.
        slots:
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
          machineUserName: requestBody.machineUserName
      - text: Let service account {machineUserName} act as {resourceRoleCrn} over {resourceCrn}.
        slots:
          machineUserName: requestBody.machineUserName
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/unassignMachineUserResourceRole'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a machine user's role on a resource
      effect: destructive
      questions:
      - How do I revoke a machine user's rights on one specific resource?
      - Does removing a service account's resource role fail when it isn't assigned?
      instructions:
      - text: Strip resource-scoped role {resourceRoleCrn} on {resourceCrn} from machine account {machineUserName}.
        slots:
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
          machineUserName: requestBody.machineUserName
      - text: Revoke service account {machineUserName}'s {resourceRoleCrn} rights on {resourceCrn}.
        slots:
          machineUserName: requestBody.machineUserName
          resourceRoleCrn: requestBody.resourceRoleCrn
          resourceCrn: requestBody.resourceCrn
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listMachineUserAssignedRoles'].post
  update:
    x-apievangelist-phrasing:
      intent: List a machine user's account roles
      effect: read
      questions:
      - What account roles has a given machine user been granted?
      - Can I audit the account-level roles of a service account?
      instructions:
      - text: Enumerate the account-wide roles carried by machine account {machineUserName}.
        slots:
          machineUserName: requestBody.machineUserName
      - text: Show which account roles the service account {machineUserName} holds.
        slots:
          machineUserName: requestBody.machineUserName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listMachineUserAssignedResourceRoles'].post
  update:
    x-apievangelist-phrasing:
      intent: List a machine user's resource roles
      effect: read
      questions:
      - Which resources does a machine user hold resource roles on?
      - Can I review a service account's per-resource permissions?
      instructions:
      - text: Audit resource-scoped grants for machine account {machineUserName}.
        slots:
          machineUserName: requestBody.machineUserName
      - text: Show the per-resource grants for service account {machineUserName}.
        slots:
          machineUserName: requestBody.machineUserName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listResourceAssignees'].post
  update:
    x-apievangelist-phrasing:
      intent: List who has roles on a resource
      effect: read
      questions:
      - Who has access to a particular CDP environment or resource, and with which role?
      - Can I list every assignee of a resource along with their resource roles?
      instructions:
      - text: List everyone assigned resource roles on {resourceCrn}.
        slots:
          resourceCrn: requestBody.resourceCrn
      - text: Show the assignees and their roles for resource {resourceCrn}, {pageSize} at a time.
        slots:
          resourceCrn: requestBody.resourceCrn
          pageSize: requestBody.pageSize
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/createMachineUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a machine user for API access
      effect: write
      questions:
      - How do I create a service account in CDP for automation scripts?
      - Can a machine user log in to the CDP console?
      instructions:
      - text: Create a machine user named {machineUserName}.
        slots:
          machineUserName: requestBody.machineUserName
      - text: Set up a new CDP service account called {machineUserName} for my pipelines.
        slots:
          machineUserName: requestBody.machineUserName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listMachineUsers'].post
  update:
    x-apievangelist-phrasing:
      intent: List machine users in the account
      effect: read
      questions:
      - What service accounts (machine users) exist in my CDP account?
      - Can I look up specific machine users by name?
      instructions:
      - text: List all machine users in my account.
      - text: Show the machine users {machineUserNames}.
        slots:
          machineUserNames: requestBody.machineUserNames
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/deleteMachineUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete a machine user
      effect: destructive
      questions:
      - What gets cleaned up when I delete a CDP machine user?
      - Does deleting a service account remove its access keys and group memberships?
      instructions:
      - text: Delete machine user {machineUserName}.
        slots:
          machineUserName: requestBody.machineUserName
      - text: Remove the service account {machineUserName} and all its access keys.
        slots:
          machineUserName: requestBody.machineUserName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/createSamlProvider'].post
  update:
    x-apievangelist-phrasing:
      intent: Register a SAML identity provider
      effect: write
      questions:
      - How do I connect my SAML identity provider to CDP for single sign-on?
      - Can I enable SCIM provisioning when adding a SAML provider?
      instructions:
      - text: Create SAML provider {samlProviderName} with metadata {samlMetadataDocument}.
        slots:
          samlProviderName: requestBody.samlProviderName
          samlMetadataDocument: requestBody.samlMetadataDocument
      - text: Add SAML provider {samlProviderName} with SCIM set to {enableScim} and group sync on login {syncGroupsOnLogin}.
        slots:
          samlProviderName: requestBody.samlProviderName
          enableScim: requestBody.enableScim
          syncGroupsOnLogin: requestBody.syncGroupsOnLogin
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/deleteSamlProvider'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete a SAML identity provider
      effect: destructive
      questions:
      - How do I remove a SAML identity provider from my CDP account?
      - Can I disconnect an old SSO provider I no longer use?
      instructions:
      - text: Delete SAML provider {samlProviderName}.
        slots:
          samlProviderName: requestBody.samlProviderName
      - text: Remove the {samlProviderName} SSO connection from CDP.
        slots:
          samlProviderName: requestBody.samlProviderName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listSamlProviders'].post
  update:
    x-apievangelist-phrasing:
      intent: List SAML identity providers
      effect: read
      questions:
      - Which SAML identity providers are configured in my CDP account?
      - Can I page through SAML providers by name?
      instructions:
      - text: List all SAML providers in my account.
      - text: List SAML providers named {samlProviderNames}.
        slots:
          samlProviderNames: requestBody.samlProviderNames
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/describeSamlProvider'].post
  update:
    x-apievangelist-phrasing:
      intent: Show one SAML provider's configuration
      effect: read
      questions:
      - What settings does a specific SAML provider have, like SCIM or group sync?
      - Can I view the full configuration of one SSO provider?
      instructions:
      - text: Describe SAML provider {samlProviderName}.
        slots:
          samlProviderName: requestBody.samlProviderName
      - text: Show the configuration of the {samlProviderName} SSO connection.
        slots:
          samlProviderName: requestBody.samlProviderName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/updateSamlProvider'].post
  update:
    x-apievangelist-phrasing:
      intent: Update a SAML provider's settings
      effect: write
      questions:
      - How do I upload new SAML metadata for an existing identity provider?
      - Can I switch on SCIM for a SAML provider that's already set up?
      instructions:
      - text: Update SAML provider {samlProviderName} with new metadata {samlMetadataDocument}.
        slots:
          samlProviderName: requestBody.samlProviderName
          samlMetadataDocument: requestBody.samlMetadataDocument
      - text: Turn workload usernames from email to {generateWorkloadUsernameByEmail} on existing SAML provider {samlProviderName}.
        slots:
          generateWorkloadUsernameByEmail: requestBody.generateWorkloadUsernameByEmail
          samlProviderName: requestBody.samlProviderName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/enableClouderaSSOLogin'].post
  update:
    x-apievangelist-phrasing:
      intent: Enable Cloudera SSO login for the account
      effect: write
      questions:
      - How do I allow all users to log in with Cloudera SSO?
      - Is turning on Cloudera SSO safe if it's already enabled?
      instructions:
      - text: Enable Cloudera SSO interactive login for my account.
      - text: Turn Cloudera SSO login back on for everyone.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/disableClouderaSSOLogin'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable Cloudera SSO login for non-admins
      effect: write
      questions:
      - Can I force users to log in through my own identity provider instead of Cloudera SSO?
      - Who can still use Cloudera SSO after it's disabled?
      instructions:
      - text: Disable Cloudera SSO login for my account.
      - text: Restrict Cloudera SSO so only account administrators can use it.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/getAccount'].post
  update:
    x-apievangelist-phrasing:
      intent: Get CDP account information
      effect: read
      questions:
      - What account-level settings does my CDP tenant have?
      - Can I retrieve information about my CDP account itself?
      instructions:
      - text: Show my CDP account information.
      - text: Get the details of the current CDP account.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/createGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a user group
      effect: write
      questions:
      - How do I create a group in CDP to manage roles for many users at once?
      - Can a group's membership sync from the identity provider on login?
      instructions:
      - text: Create a group called {groupName}.
        slots:
          groupName: requestBody.groupName
      - text: Create group {groupName} with sync-membership-on-login set to {syncMembershipOnUserLogin}.
        slots:
          groupName: requestBody.groupName
          syncMembershipOnUserLogin: requestBody.syncMembershipOnUserLogin
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/deleteGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete a user group
      effect: destructive
      questions:
      - How do I delete a CDP group I no longer need?
      - Can I remove an obsolete group from my account?
      instructions:
      - text: Delete group {groupName}.
        slots:
          groupName: requestBody.groupName
      - text: Remove the {groupName} group from CDP.
        slots:
          groupName: requestBody.groupName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/listGroups'].post
  update:
    x-apievangelist-phrasing:
      intent: List groups in the account
      effect: read
      questions:
      - What groups exist in my CDP account?
      - Can I look up a few specific groups by name?
      instructions:
      - text: List all groups in my CDP account.
      - text: Show the groups {groupNames}.
        slots:
          groupNames: requestBody.groupNames
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/updateGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Change a group's membership sync setting
      effect: write
      questions:
      - Can I change whether an existing group syncs its members when users log in?
      - Is there a way to edit a group's settings after creating it?
      instructions:
      - text: Set sync-membership-on-login to {syncMembershipOnUserLogin} for existing group {groupName}.
        slots:
          syncMembershipOnUserLogin: requestBody.syncMembershipOnUserLogin
          groupName: requestBody.groupName
      - text: Update group {groupName} so login no longer syncs membership.
        slots:
          groupName: requestBody.groupName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/addUserToGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a user to a group
      effect: write
      questions:
      - How do I put a human user into a CDP group?
      - Does adding someone to a group give them the group's roles?
      instructions:
      - text: Add user {userId} to group {groupName}.
        slots:
          userId: requestBody.userId
          groupName: requestBody.groupName
      - text: Make {userId} a member of the {groupName} group.
        slots:
          userId: requestBody.userId
          groupName: requestBody.groupName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/addMachineUserToGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a machine user to a group
      effect: write
      questions:
      - Can a service account be a member of a CDP group?
      - How do I give a machine user a group's permissions?
      instructions:
      - text: Add machine user {machineUserName} to group {groupName}.
        slots:
          machineUserName: requestBody.machineUserName
          groupName: requestBody.groupName
      - text: Put the service account {machineUserName} into {groupName}.
        slots:
          machineUserName: requestBody.machineUserName
          groupName: requestBody.groupName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/removeUserFromGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a user from a group
      effect: destructive
      questions:
      - How do I take a person out of a CDP group?
      - Will removing a user from a group drop the roles they got through it?
      instructions:
      - text: Remove user {userId} from group {groupName}.
        slots:
          userId: requestBody.userId
          groupName: requestBody.groupName
      - text: Take {userId} out of the {groupName} group.
        slots:
          userId: requestBody.userId
          groupName: requestBody.groupName
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/removeMachineUserFromGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a machine user from a group
      effect: destructive
      questions:
      - Can I pull a service account out of a group?
      - How do I stop a machine user inheriting a group's roles?
      instructions:
      - text: Remove machine user {machineUserName} from group {groupName}.
        slots:
          machineUserName: requestBody.machineUserName
          groupName: requestBody.groupName
      - text: Take the service account {machineUserName} out of {groupName}.
        slots:
          machineUserName: requestBody.machineUserName
          groupName: requestBody.groupName
      method: generated
      generated: '2026-10-01'


# --- truncated at 32 KB (54 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cloudera/refs/heads/main/overlays/cloudera-iam-api-phrasing-overlay.yaml