Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks IAM API
22 actions
22 updates
phrasing
extends
openapi/palo-alto-networks-iam-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 22 · first 16 shown; the file carries all of them
$.info
$.paths['/api/v1/permission'].post
$.paths['/api/v1/permission/page'].post
$.paths['/api/v1/permission/access'].post
$.paths['/api/v1/permission/access/page'].post
$.paths['/api/v1/permission/alert/remediation'].post
$.paths['/api/v1/permission/alert/search'].get
$.paths['/api/v1/suggest'].post
$.paths['/iam/api/v3/search/permission'].post
$.paths['/iam/api/v4/search/permission'].post
$.paths['/iam/api/v3/permission/{permission-id}/list_access'].post
$.paths['/iam/api/v2/suggestion'].post
$.paths['/iam/api/v2/search/iam_config'].post
$.paths['/iam/api/v1/asset/{asset-id}/related-asset'].post
$.paths['/iam/api/v2/alert/{alertId}/remediation_command'].get
$.paths['/iam/api/v2/alert/{alertId}/query'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks IAM API
version: 1.0.0
extends: openapi/palo-alto-networks-iam-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 21
- target: $.paths['/api/v1/permission'].post
update:
x-apievangelist-phrasing:
intent: Run an IAM query to list permissions
effect: read
questions:
- How do I run an IAM query in Prisma Cloud to see who can access what?
- Can I cap how many permission results the original IAM permission search returns?
instructions:
- text: Run IAM query {query} and return the first {limit} permissions.
slots:
query: requestBody.query
limit: requestBody.limit
- text: Execute the v1 IAM permission query {query} with a limit of {limit}.
slots:
query: requestBody.query
limit: requestBody.limit
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v1/permission/page'].post
update:
x-apievangelist-phrasing:
intent: Get the next page of IAM permission results
effect: read
questions:
- What do I pass to fetch the next page after a v1 IAM permissions query?
- Can I page through more permission rows using the token from my last query?
instructions:
- text: Fetch the next page of permissions using page token {pageToken}.
slots:
pageToken: requestBody.pageToken
- text: Continue the v1 permissions results from token {pageToken}, {limit} rows at a time.
slots:
pageToken: requestBody.pageToken
limit: requestBody.limit
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v1/permission/access'].post
update:
x-apievangelist-phrasing:
intent: See when a permission was last used
effect: read
questions:
- How can I tell when a specific IAM permission was actually last used?
- Is there a way to see last-access data for one permission ID under an IAM query?
instructions:
- text: Show last-access usage for permission {permissionId} under query {query}.
slots:
permissionId: requestBody.permissionId
query: requestBody.query
- text: Get up to {limit} last-access records for permission {permissionId} matching {query}.
slots:
limit: requestBody.limit
permissionId: requestBody.permissionId
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v1/permission/access/page'].post
update:
x-apievangelist-phrasing:
intent: Get the next page of permission last-access data
effect: read
questions:
- How do I keep paging through permission last-access results in v1?
- Can I continue a permission usage listing with the token it returned?
instructions:
- text: Get the next page of permission access records with token {pageToken}.
slots:
pageToken: requestBody.pageToken
- text: Continue listing permission last-access data from token {pageToken}.
slots:
pageToken: requestBody.pageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v1/permission/alert/remediation'].post
update:
x-apievangelist-phrasing:
intent: Get remediations for IAM alerts
effect: read
questions:
- How do I get suggested remediations for a batch of IAM alerts?
- Can I fetch fixes for several alert IDs in a single call?
instructions:
- text: Get remediations for alerts {alerts}.
slots:
alerts: requestBody.alerts
- text: List the remediation steps for IAM alert IDs {alerts}.
slots:
alerts: requestBody.alerts
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v1/permission/alert/search'].get
update:
x-apievangelist-phrasing:
intent: Get the IAM query behind an alert
effect: read
questions:
- Which IAM query triggered a given alert, using the original v1 lookup?
- Can I see the RQL an IAM alert was raised from by passing its alert ID as a query parameter?
instructions:
- text: Show the IAM query for alert {alertId} with the v1 search endpoint.
slots:
alertId: query.alertId
- text: Look up the RQL behind alert {alertId}.
slots:
alertId: query.alertId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v1/suggest'].post
update:
x-apievangelist-phrasing:
intent: Get autocomplete suggestions for an IAM query
effect: read
questions:
- How can I tell whether my partial IAM query is valid yet?
- What can I append to a half-written IAM query to complete it in the v1 suggest endpoint?
instructions:
- text: Suggest completions for the partial IAM query {query}.
slots:
query: requestBody.query
- text: Check if {query} is a valid IAM query and suggest what comes next.
slots:
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v3/search/permission'].post
update:
x-apievangelist-phrasing:
intent: Search IAM permissions with the v3 API
effect: read
questions:
- How do I search permissions with the v3 IAM search and get a next page token?
- Can I limit the page size when searching permissions in v3?
instructions:
- text: Search permissions in v3 with query {query}.
slots:
query: requestBody.query
- text: Run v3 permission search {query}, {limit} per page, continuing from token {nextPageToken}.
slots:
query: requestBody.query
limit: query.limit
nextPageToken: requestBody.nextPageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v4/search/permission'].post
update:
x-apievangelist-phrasing:
intent: Search permissions grouped by fields (v4)
effect: read
questions:
- Can I group IAM permission search results by specific fields?
- What does the v4 permission search return compared to a flat list?
instructions:
- text: Search permissions with query {query} grouped by {groupByFields}.
slots:
query: requestBody.query
groupByFields: requestBody.groupByFields
- text: Run a v4 grouped permission search for {query}.
slots:
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v3/permission/{permission-id}/list_access'].post
update:
x-apievangelist-phrasing:
intent: List last accesses of a permission (v3)
effect: read
questions:
- How do I list the recent accesses for one permission ID in the v3 API?
- Can I page through a permission's last-access history with a token?
instructions:
- text: List v3 last accesses for permission {permission_id} filtered by {query}.
slots:
permission_id: path.permission-id
query: requestBody.query
- text: Get the next {limit} accesses of permission {permission_id} from token {nextPageToken}.
slots:
limit: query.limit
permission_id: path.permission-id
nextPageToken: requestBody.nextPageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v2/suggestion'].post
update:
x-apievangelist-phrasing:
intent: Autocomplete an RQL query (v2)
effect: read
questions:
- Is there a newer suggestion endpoint that autocompletes RQL and flags invalid queries?
- How do I get v2 autocomplete hints for the RQL I'm typing?
instructions:
- text: Autocomplete RQL {query} using v2 suggestions.
slots:
query: requestBody.query
- text: Tell me whether RQL {query} is valid via the v2 suggestion service.
slots:
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v2/search/iam_config'].post
update:
x-apievangelist-phrasing:
intent: Get the raw role or policy behind a permission
effect: read
questions:
- Can I see the raw policy or role definition a permission was calculated from?
- Where does a given IAM permission come from in the underlying config?
instructions:
- text: Show the raw policy or role definition for permission {permissionId}.
slots:
permissionId: requestBody.permissionId
- text: Get the source IAM config for permission {permissionId}.
slots:
permissionId: requestBody.permissionId
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v1/asset/{asset-id}/related-asset'].post
update:
x-apievangelist-phrasing:
intent: List assets related to a cloud identity
effect: read
questions:
- What other assets are related to a Cloud Identity Inventory resource?
- Can I filter an identity's related assets by relationship type and last access time?
instructions:
- text: List assets related to identity asset {asset_id}.
slots:
asset_id: path.asset-id
- text: Show {relationshipType} related assets for {asset_id} accessed after {lastAccessFromTime}.
slots:
relationshipType: requestBody.relationshipType
asset_id: path.asset-id
lastAccessFromTime: requestBody.lastAccessFromTime
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v2/alert/{alertId}/remediation_command'].get
update:
x-apievangelist-phrasing:
intent: Get the remediation command for an alert
effect: read
questions:
- Is there a ready-made CLI command to remediate a specific IAM alert?
- How do I get the fix command for one alert ID?
instructions:
- text: Get the remediation command for alert {alertId}.
slots:
alertId: path.alertId
- text: Give me the command that fixes alert {alertId}.
slots:
alertId: path.alertId
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v2/alert/{alertId}/query'].get
update:
x-apievangelist-phrasing:
intent: Get the query for an alert instance (v2)
effect: read
questions:
- How do I investigate an alert by pulling the query tied to that alert instance in v2?
- Can I get the v2 IAM query associated with an alert from its path ID?
instructions:
- text: Get the v2 query associated with alert {alertId}.
slots:
alertId: path.alertId
- text: Investigate alert {alertId} by retrieving its IAM query.
slots:
alertId: path.alertId
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v1/assets/{assetId}/over-permissive-metadata'].get
update:
x-apievangelist-phrasing:
intent: Check least-privilege potential for an asset
effect: read
questions:
- Is this asset over-permissive, and how much could least privilege improve it?
- What metadata is available about least-privilege improvement for an asset?
instructions:
- text: Show least-privilege improvement metadata for asset {assetId}.
slots:
assetId: path.assetId
- text: Check whether asset {assetId} is over-permissive.
slots:
assetId: path.assetId
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v1/assets/{assetId}/existing-least-privileged-access'].get
update:
x-apievangelist-phrasing:
intent: Suggest least privilege from existing roles for an asset
effect: read
questions:
- Can I right-size an asset's access using only roles and policies that already exist?
- How many days of activity does the existing-roles least-privilege suggestion look back over?
instructions:
- text: Suggest least privilege for asset {assetId} from existing policies over the last {lookback_duration_days} days as {output_format}.
slots:
assetId: path.assetId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
- text: Recommend existing roles for asset {assetId}, {lookback_duration_days}-day lookback, {output_format} output.
slots:
assetId: path.assetId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v1/assets/{assetId}/custom-least-privileged-access'].get
update:
x-apievangelist-phrasing:
intent: Generate a custom least-privilege policy for an asset
effect: read
questions:
- Can Prisma Cloud generate a brand-new least-privilege policy for an asset?
- Which output formats can a custom least-privilege config for an asset come in?
instructions:
- text: Generate a custom least-privilege config for asset {assetId} from {lookback_duration_days} days of use in {output_format}.
slots:
assetId: path.assetId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
- text: Create a new tailored policy for asset {assetId} covering {lookback_duration_days} days, format {output_format}.
slots:
assetId: path.assetId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v1/resources/{resourceId}/over-permissive-metadata'].get
update:
x-apievangelist-phrasing:
intent: Check least-privilege potential for a resource
effect: read
questions:
- Does a particular cloud resource have room for access optimization?
- Where can I see over-permissive metadata keyed by resource ID rather than asset ID?
instructions:
- text: Show over-permissive metadata for resource {resourceId}.
slots:
resourceId: path.resourceId
- text: Check if resource {resourceId} could have its access tightened.
slots:
resourceId: path.resourceId
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v1/resources/{resourceId}/existing-least-privileged-access'].get
update:
x-apievangelist-phrasing:
intent: Suggest least privilege from existing roles for a resource
effect: read
questions:
- Can I tighten a resource's access by reusing its current IAM configurations?
- How do I get existing-policy least-privilege suggestions by resource ID?
instructions:
- text: Suggest existing-role least privilege for resource {resourceId} over {lookback_duration_days} days in {output_format}.
slots:
resourceId: path.resourceId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
- text: Recommend current policies to keep for resource {resourceId}, lookback {lookback_duration_days} days, as {output_format}.
slots:
resourceId: path.resourceId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/api/v1/resources/{resourceId}/custom-least-privileged-access'].get
update:
x-apievangelist-phrasing:
intent: Generate a custom least-privilege policy for a resource
effect: read
questions:
- Can I generate a new custom least-privilege config for a specific resource?
- What would a tailored minimal policy look like for a resource based on recent actions?
instructions:
- text: Generate a custom least-privilege policy for resource {resourceId} from {lookback_duration_days} days in {output_format}.
slots:
resourceId: path.resourceId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
- text: Build a new minimal access config for resource {resourceId}, {lookback_duration_days}-day window, {output_format} format.
slots:
resourceId: path.resourceId
lookback_duration_days: query.lookback_duration_days
output_format: query.output_format
method: generated
generated: '2026-09-26'