Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Access Policies API
10 actions
10 updates
phrasing
extends
openapi/palo-alto-networks-access-policies-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 10
$.info
$.paths['/access-policies'].get
$.paths['/access-policies'].post
$.paths['/access-policies/{id}'].get
$.paths['/access-policies/{id}'].put
$.paths['/access-policies/{id}'].delete
$.paths['/iam/v1/access_policies'].get
$.paths['/iam/v1/access_policies'].post
$.paths['/iam/v1/access_policies/{id}'].get
$.paths['/iam/v1/access_policies/{id}'].delete
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Access Policies API
version: 1.0.0
extends: openapi/palo-alto-networks-access-policies-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 9
- target: $.paths['/access-policies'].get
update:
x-apievangelist-phrasing:
intent: List access policies for a tenant
effect: read
questions:
- Which roles has each service account or user been granted across my tenant service groups?
- Can I list the access policies for one principal or one TSG?
instructions:
- text: List access policies for principal {principal_id}.
slots:
principal_id: query.principal_id
- text: Show access policies scoped to TSG {tsg_id}.
slots:
tsg_id: query.tsg_id
method: generated
generated: '2026-09-26'
- target: $.paths['/access-policies'].post
update:
x-apievangelist-phrasing:
intent: Grant a role to a principal in a TSG
effect: write
questions:
- How do I give a service account a role within a tenant service group?
- What do I need to bind a user to a role for API access?
instructions:
- text: Grant role {role_id} to {principal_type} {principal_id} in TSG {tsg_id}.
slots:
role_id: requestBody.role_id
principal_type: requestBody.principal_type
principal_id: requestBody.principal_id
tsg_id: requestBody.tsg_id
- text: Create an access policy binding {principal_type} {principal_id} to role {role_id} on tenant {tsg_id}.
slots:
principal_type: requestBody.principal_type
principal_id: requestBody.principal_id
role_id: requestBody.role_id
tsg_id: requestBody.tsg_id
method: generated
generated: '2026-09-26'
- target: $.paths['/access-policies/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an access policy
effect: read
questions:
- Which principal, role and TSG does one access policy bind?
- What details are stored on a specific access policy?
instructions:
- text: Get access policy {id}.
slots:
id: path.id
- text: Show the role binding in access policy {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/access-policies/{id}'].put
update:
x-apievangelist-phrasing:
intent: Change the role on an access policy
effect: write
questions:
- Can I switch a principal to a different role without recreating the access policy?
- How do I update an existing role assignment?
instructions:
- text: Change access policy {id} to role {role_id} for {principal_type} {principal_id} in TSG {tsg_id}.
slots:
id: path.id
role_id: requestBody.role_id
principal_type: requestBody.principal_type
principal_id: requestBody.principal_id
tsg_id: requestBody.tsg_id
- text: Update the role assignment on policy {id} to {role_id}, keeping principal {principal_id} ({principal_type}) and TSG {tsg_id}.
slots:
id: path.id
role_id: requestBody.role_id
principal_id: requestBody.principal_id
principal_type: requestBody.principal_type
tsg_id: requestBody.tsg_id
method: generated
generated: '2026-09-26'
- target: $.paths['/access-policies/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Revoke an access policy
effect: destructive
questions:
- Can I revoke a role binding from a service account?
- Does deleting an access policy remove the principal's permissions?
instructions:
- text: Delete access policy {id}.
slots:
id: path.id
- text: Revoke the role binding in access policy {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/v1/access_policies'].get
update:
x-apievangelist-phrasing:
intent: List IAM access policies
effect: read
questions:
- Which access policies grant a particular role in my tenant?
- What roles has a specific user or service account been assigned?
instructions:
- text: List all access policies using role {role}.
slots:
role: query.role
- text: Show access policies assigned to {principal}.
slots:
principal: query.principal
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/access_policies'].post
update:
x-apievangelist-phrasing:
intent: Assign an access policy to a user
effect: write
questions:
- How do I give a user or service account a role on a tenant service group?
- Does assigning an access policy to an unknown email create an SSO account?
instructions:
- text: Assign role {role} to {principal} on resource {resource}.
slots:
role: requestBody.role
principal: requestBody.principal
resource: requestBody.resource
- text: Grant {principal} the {role} role for TSG {resource}.
slots:
principal: requestBody.principal
role: requestBody.role
resource: requestBody.resource
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/access_policies/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an access policy
effect: read
questions:
- What role and principal does a specific access policy contain?
- Can I look up one IAM access policy by ID?
instructions:
- text: Get access policy {id} from the IAM v1 path.
slots:
id: path.id
- text: Show who access policy {id} applies to.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/access_policies/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Revoke an access policy
effect: destructive
questions:
- Can I remove a user's role by deleting their access policy?
- What access is lost when an access policy is deleted?
instructions:
- text: Delete access policy {id} using the IAM v1 endpoint.
slots:
id: path.id
- text: Revoke the role granted by access policy {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'