# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Endpoint Detection and Response (EDR) Incidents API version: 1.0.0 extends: openapi/acronis-incidents-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 6 - target: $.paths['/incidents'].get update: x-apievangelist-phrasing: intent: List security incidents for customers effect: read questions: - How do I pull all incidents for my customers into my MDR backend? - Can I filter incidents by severity or by when they were last updated? - Which incidents have not been mitigated yet? instructions: - text: List incidents for customer {customer_id}. slots: customer_id: query.customer_id - text: Get incidents with severity {severity} updated in {updated_at}. slots: severity: query.severity updated_at: query.updated_at - text: Fetch the next page of incidents from cursor {cursor}. slots: cursor: query.cursor method: generated generated: '2026-10-01' - target: $.paths['/incidents/investigation_state'].post update: x-apievangelist-phrasing: intent: Update investigation state on many incidents effect: write questions: - How do I set the investigation state of several incidents in one call? - Can I post the same comment across a batch of incidents? instructions: - text: Set investigation update {update} on incidents {incident_ids}. slots: update: requestBody.update incident_ids: requestBody.incident_ids - text: Apply update {update} to each customer and incident pair in {customer_incident_ids}. slots: update: requestBody.update customer_incident_ids: requestBody.customer_incident_ids method: generated generated: '2026-10-01' - target: $.paths['/incidents/{incident_id}'].get update: x-apievangelist-phrasing: intent: Get one incident's details effect: read questions: - What detections and activities make up a specific incident? - Can I see which response actions are available for an incident? instructions: - text: Show incident {incident_id}. slots: incident_id: path.incident_id - text: Get incident {incident_id} for customer {customer_id} with its detections and activities. slots: incident_id: path.incident_id customer_id: query.customer_id method: generated generated: '2026-10-01' - target: $.paths['/incidents/{incident_id}/investigation_state'].post update: x-apievangelist-phrasing: intent: Update one incident's investigation state effect: write questions: - How do I move a single incident to a new investigation state with a comment? - Can I link an incident to my external ticket and assignee? instructions: - text: Set incident {incident_id} investigation state to {state}. slots: incident_id: path.incident_id state: requestBody.state - text: Comment {comment} on incident {incident_id}. slots: incident_id: path.incident_id comment: requestBody.comment - text: Attach ticket {ticket_id} assigned to {assignee} to incident {incident_id}. slots: incident_id: path.incident_id ticket_id: requestBody.ticket_id assignee: requestBody.assignee method: generated generated: '2026-10-01' - target: $.paths['/incidents/{incident_id}/response_action'].get update: x-apievangelist-phrasing: intent: Check the status of a response action effect: read questions: - Did the isolation action I started on an incident finish? - What is the detailed status of a response action I already triggered? instructions: - text: Show the status of response action {activity_id} on incident {incident_id}. slots: activity_id: query.activity_id incident_id: path.incident_id - text: Check whether action activity {activity_id} for incident {incident_id} completed. slots: activity_id: query.activity_id incident_id: path.incident_id method: generated generated: '2026-10-01' - target: $.paths['/incidents/{incident_id}/response_action'].post update: x-apievangelist-phrasing: intent: Run a response action on an incident effect: write questions: - How do I isolate a compromised workload from an incident? - Can I delay a response action by some minutes before it runs? instructions: - text: Perform action {action} on incident {incident_id}. slots: action: query.action incident_id: path.incident_id - text: Run {action} for incident {incident_id} on workload {workload_id} after {delay} minutes. slots: action: query.action incident_id: path.incident_id workload_id: query.workload_id delay: query.delay method: generated generated: '2026-10-01'