Tenable · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Identity Exposure Deviance API
13 actions
13 updates
phrasing
extends
openapi/tenable-deviance-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Tenable's API. It is a proposal applied on top of the contract, not a document Tenable publishes.
What the actions change
x-apievangelist-phrasing
Targets 13
$.info
$.paths['/api/deviances/changed'].get
$.paths['/api/directories/{directoryId}/deviances/{id}'].get
$.paths['/api/export/profiles/{profileId}/checkers/{checkerId}'].get
$.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances'].get
$.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances/{id}'].get
$.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances/{id}'].patch
$.paths['/api/profiles/{profileId}/infrastructures/{infrastructureId}/directories/{directoryId}/checkers/{checkerId}/deviances'].get
$.paths['/api/profiles/{profileId}/checkers/{checkerId}/deviances'].post
$.paths['/api/profiles/{profileId}/checkers/{checkerId}/deviances'].patch
$.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/{adObjectId}/deviances'].post
$.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/{adObjectId}/deviances'].patch
$.paths['/api/profiles/{profileId}/infrastructures/{infrastructureId}/directories/{directoryId}/events/{eventId}/deviances'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Identity Exposure Deviance API
version: 1.0.0
extends: openapi/tenable-deviance-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 12
- target: $.paths['/api/deviances/changed'].get
update:
x-apievangelist-phrasing:
intent: List deviances created or resolved since an event
effect: read
questions:
- Which deviances appeared or got resolved since the last event I processed?
- Can I poll for newly created and resolved deviances incrementally?
instructions:
- text: List deviances created or resolved since the last event.
- text: Show changed deviances since my last sync.
method: generated
generated: '2026-10-01'
- target: $.paths['/api/directories/{directoryId}/deviances/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a deviance history entry in a directory
effect: read
questions:
- How do I look up one deviance history record by id within a directory?
- What is the history of a single deviance in a domain?
instructions:
- text: Get deviance {id} in directory {directoryId}.
slots:
id: path.id
directoryId: path.directoryId
- text: Show history record {id} for directory {directoryId}, no forest needed.
slots:
id: path.id
directoryId: path.directoryId
method: generated
generated: '2026-10-01'
- target: $.paths['/api/export/profiles/{profileId}/checkers/{checkerId}'].get
update:
x-apievangelist-phrasing:
intent: Export a checker's deviant objects as CSV
effect: read
questions:
- Can I download all AD objects failing an indicator as CSV?
- How do I export deviances for one checker in my language?
instructions:
- text: Export deviant objects for checker {checkerId} in profile {profileId} as CSV.
slots:
checkerId: path.checkerId
profileId: path.profileId
- text: Download the checker {checkerId} deviance CSV for profile {profileId} in {language}.
slots:
checkerId: path.checkerId
profileId: path.profileId
language: query.language
method: generated
generated: '2026-10-01'
- target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances'].get
update:
x-apievangelist-phrasing:
intent: List deviances in a directory
effect: read
questions:
- Which deviances exist across one domain, regardless of checker?
- Can I page through only resolved deviances for a directory?
instructions:
- text: List deviances for directory {directoryId} in forest {infrastructureId}.
slots:
directoryId: path.directoryId
infrastructureId: path.infrastructureId
- text: Show resolved={resolved} deviances in directory {directoryId} of forest {infrastructureId}.
slots:
resolved: query.resolved
directoryId: path.directoryId
infrastructureId: path.infrastructureId
method: generated
generated: '2026-10-01'
- target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a deviance history entry in a forest
effect: read
questions:
- How do I read one deviance record when I know its forest and domain?
- When was a specific deviance in a forest's directory first seen?
instructions:
- text: Get deviance {id} in directory {directoryId} of forest {infrastructureId}.
slots:
id: path.id
directoryId: path.directoryId
infrastructureId: path.infrastructureId
- text: Show deviance history {id} from infrastructure {infrastructureId}, domain {directoryId}.
slots:
id: path.id
directoryId: path.directoryId
infrastructureId: path.infrastructureId
method: generated
generated: '2026-10-01'
- target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances/{id}'].patch
update:
x-apievangelist-phrasing:
intent: Ignore one deviance until a date
effect: write
questions:
- Can I snooze a single deviance until a certain date?
- How do I ignore one specific deviance temporarily?
instructions:
- text: Ignore deviance {id} in directory {directoryId} of forest {infrastructureId} until {ignoreUntil}.
slots:
id: path.id
directoryId: path.directoryId
infrastructureId: path.infrastructureId
ignoreUntil: requestBody.ignoreUntil
- text: Snooze deviance {id} in {infrastructureId}/{directoryId} until {ignoreUntil}.
slots:
id: path.id
directoryId: path.directoryId
infrastructureId: path.infrastructureId
ignoreUntil: requestBody.ignoreUntil
method: generated
generated: '2026-10-01'
- target: $.paths['/api/profiles/{profileId}/infrastructures/{infrastructureId}/directories/{directoryId}/checkers/{checkerId}/deviances'].get
update:
x-apievangelist-phrasing:
intent: List a checker's deviances in one directory
effect: read
questions:
- Which deviances does one indicator raise in a single domain?
- Can I narrow a checker's findings to one directory?
instructions:
- text: List deviances of checker {checkerId} in directory {directoryId}, forest {infrastructureId}, profile {profileId}.
slots:
checkerId: path.checkerId
directoryId: path.directoryId
infrastructureId: path.infrastructureId
profileId: path.profileId
- text: Show page {page} of checker {checkerId} findings for domain {directoryId} in {infrastructureId} under profile {profileId}.
slots:
page: query.page
checkerId: path.checkerId
directoryId: path.directoryId
infrastructureId: path.infrastructureId
profileId: path.profileId
method: generated
generated: '2026-10-01'
- target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/deviances'].post
update:
x-apievangelist-phrasing:
intent: Query deviances for a checker
effect: read
questions:
- How do I get all deviances an indicator raised across every domain?
- Can I filter a checker's deviances with an expression?
instructions:
- text: Get deviances for checker {checkerId} in profile {profileId} matching {expression}.
slots:
checkerId: path.checkerId
profileId: path.profileId
expression: requestBody.expression
- text: Query all directories for checker {checkerId} deviances in profile {profileId} using filter {expression}.
slots:
checkerId: path.checkerId
profileId: path.profileId
expression: requestBody.expression
method: generated
generated: '2026-10-01'
- target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/deviances'].patch
update:
x-apievangelist-phrasing:
intent: Ignore all deviances of a checker
effect: write
questions:
- Can I ignore every deviance from one indicator until a date?
- How do I bulk-snooze a checker's findings for a profile?
instructions:
- text: Ignore all deviances of checker {checkerId} in profile {profileId} until {ignoreUntil}.
slots:
checkerId: path.checkerId
profileId: path.profileId
ignoreUntil: requestBody.ignoreUntil
- text: Bulk snooze checker {checkerId} findings under profile {profileId} until {ignoreUntil}.
slots:
checkerId: path.checkerId
profileId: path.profileId
ignoreUntil: requestBody.ignoreUntil
method: generated
generated: '2026-10-01'
- target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/{adObjectId}/deviances'].post
update:
x-apievangelist-phrasing:
intent: Search a checker's deviances on one AD object
effect: read
questions:
- What deviances has a single AD object accumulated for one indicator?
- Can I see deviance history on an object within a date range?
instructions:
- text: Search deviances on AD object {adObjectId} for checker {checkerId} in profile {profileId}, ignored {showIgnored}.
slots:
adObjectId: path.adObjectId
checkerId: path.checkerId
profileId: path.profileId
showIgnored: requestBody.showIgnored
- text: Show object {adObjectId} deviances for checker {checkerId}, profile {profileId}, from {dateStart} to {dateEnd}.
slots:
adObjectId: path.adObjectId
checkerId: path.checkerId
profileId: path.profileId
dateStart: requestBody.dateStart
dateEnd: requestBody.dateEnd
method: generated
generated: '2026-10-01'
- target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/{adObjectId}/deviances'].patch
update:
x-apievangelist-phrasing:
intent: Ignore a checker's deviances on one AD object
effect: write
questions:
- How do I ignore the deviances one indicator raised on a single object?
- Can I snooze an object's findings only for certain reasons?
instructions:
- text: Ignore checker {checkerId} deviances on object {adObjectId} in profile {profileId} until {ignoreUntil}.
slots:
checkerId: path.checkerId
adObjectId: path.adObjectId
profileId: path.profileId
ignoreUntil: requestBody.ignoreUntil
- text: Snooze object {adObjectId} findings for reasons {reasonIds} on checker {checkerId}, profile {profileId}, until {ignoreUntil}.
slots:
adObjectId: path.adObjectId
reasonIds: query.reasonIds
checkerId: path.checkerId
profileId: path.profileId
ignoreUntil: requestBody.ignoreUntil
method: generated
generated: '2026-10-01'
- target: $.paths['/api/profiles/{profileId}/infrastructures/{infrastructureId}/directories/{directoryId}/events/{eventId}/deviances'].post
update:
x-apievangelist-phrasing:
intent: List deviances caused by an event
effect: read
questions:
- Which deviances did a specific AD change event introduce?
- Can I filter an event's deviances by checker and reason?
instructions:
- text: Get deviances from event {eventId} in directory {directoryId}, forest {infrastructureId}, profile {profileId} for checkers {checkers} and reasons {reasons}.
slots:
eventId: path.eventId
directoryId: path.directoryId
infrastructureId: path.infrastructureId
profileId: path.profileId
checkers: requestBody.checkers
reasons: requestBody.reasons
- text: Show what event {eventId} broke in {infrastructureId}/{directoryId} under profile {profileId}.
slots:
eventId: path.eventId
directoryId: path.directoryId
infrastructureId: path.infrastructureId
profileId: path.profileId
method: generated
generated: '2026-10-01'