Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Access Policies API

10 actions 10 updates phrasing extends openapi/palo-alto-networks-access-policies-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 10

$.info
$.paths['/access-policies'].get
$.paths['/access-policies'].post
$.paths['/access-policies/{id}'].get
$.paths['/access-policies/{id}'].put
$.paths['/access-policies/{id}'].delete
$.paths['/iam/v1/access_policies'].get
$.paths['/iam/v1/access_policies'].post
$.paths['/iam/v1/access_policies/{id}'].get
$.paths['/iam/v1/access_policies/{id}'].delete

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Access Policies API
  version: 1.0.0
extends: openapi/palo-alto-networks-access-policies-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 9
- target: $.paths['/access-policies'].get
  update:
    x-apievangelist-phrasing:
      intent: List access policies for a tenant
      effect: read
      questions:
      - Which roles has each service account or user been granted across my tenant service groups?
      - Can I list the access policies for one principal or one TSG?
      instructions:
      - text: List access policies for principal {principal_id}.
        slots:
          principal_id: query.principal_id
      - text: Show access policies scoped to TSG {tsg_id}.
        slots:
          tsg_id: query.tsg_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/access-policies'].post
  update:
    x-apievangelist-phrasing:
      intent: Grant a role to a principal in a TSG
      effect: write
      questions:
      - How do I give a service account a role within a tenant service group?
      - What do I need to bind a user to a role for API access?
      instructions:
      - text: Grant role {role_id} to {principal_type} {principal_id} in TSG {tsg_id}.
        slots:
          role_id: requestBody.role_id
          principal_type: requestBody.principal_type
          principal_id: requestBody.principal_id
          tsg_id: requestBody.tsg_id
      - text: Create an access policy binding {principal_type} {principal_id} to role {role_id} on tenant {tsg_id}.
        slots:
          principal_type: requestBody.principal_type
          principal_id: requestBody.principal_id
          role_id: requestBody.role_id
          tsg_id: requestBody.tsg_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/access-policies/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an access policy
      effect: read
      questions:
      - Which principal, role and TSG does one access policy bind?
      - What details are stored on a specific access policy?
      instructions:
      - text: Get access policy {id}.
        slots:
          id: path.id
      - text: Show the role binding in access policy {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/access-policies/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Change the role on an access policy
      effect: write
      questions:
      - Can I switch a principal to a different role without recreating the access policy?
      - How do I update an existing role assignment?
      instructions:
      - text: Change access policy {id} to role {role_id} for {principal_type} {principal_id} in TSG {tsg_id}.
        slots:
          id: path.id
          role_id: requestBody.role_id
          principal_type: requestBody.principal_type
          principal_id: requestBody.principal_id
          tsg_id: requestBody.tsg_id
      - text: Update the role assignment on policy {id} to {role_id}, keeping principal {principal_id} ({principal_type}) and TSG {tsg_id}.
        slots:
          id: path.id
          role_id: requestBody.role_id
          principal_id: requestBody.principal_id
          principal_type: requestBody.principal_type
          tsg_id: requestBody.tsg_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/access-policies/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Revoke an access policy
      effect: destructive
      questions:
      - Can I revoke a role binding from a service account?
      - Does deleting an access policy remove the principal's permissions?
      instructions:
      - text: Delete access policy {id}.
        slots:
          id: path.id
      - text: Revoke the role binding in access policy {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/iam/v1/access_policies'].get
  update:
    x-apievangelist-phrasing:
      intent: List IAM access policies
      effect: read
      questions:
      - Which access policies grant a particular role in my tenant?
      - What roles has a specific user or service account been assigned?
      instructions:
      - text: List all access policies using role {role}.
        slots:
          role: query.role
      - text: Show access policies assigned to {principal}.
        slots:
          principal: query.principal
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/v1/access_policies'].post
  update:
    x-apievangelist-phrasing:
      intent: Assign an access policy to a user
      effect: write
      questions:
      - How do I give a user or service account a role on a tenant service group?
      - Does assigning an access policy to an unknown email create an SSO account?
      instructions:
      - text: Assign role {role} to {principal} on resource {resource}.
        slots:
          role: requestBody.role
          principal: requestBody.principal
          resource: requestBody.resource
      - text: Grant {principal} the {role} role for TSG {resource}.
        slots:
          principal: requestBody.principal
          role: requestBody.role
          resource: requestBody.resource
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/v1/access_policies/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an access policy
      effect: read
      questions:
      - What role and principal does a specific access policy contain?
      - Can I look up one IAM access policy by ID?
      instructions:
      - text: Get access policy {id} from the IAM v1 path.
        slots:
          id: path.id
      - text: Show who access policy {id} applies to.
        slots:
          id: path.id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/iam/v1/access_policies/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Revoke an access policy
      effect: destructive
      questions:
      - Can I remove a user's role by deleting their access policy?
      - What access is lost when an access policy is deleted?
      instructions:
      - text: Delete access policy {id} using the IAM v1 endpoint.
        slots:
          id: path.id
      - text: Revoke the role granted by access policy {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-10-01'