# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Aembit Cloud Access Policy (Deprecated) API version: 1.0.0 extends: openapi/aembit-access-policy-deprecated-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 8 - target: $.paths['/api/v1/access-policies/{id}'].get update: x-apievangelist-phrasing: intent: Get an access policy (v1) effect: read questions: - What does an access policy connect, in the older v1 API? - Can I read one access policy by its ID with the v1 endpoint? instructions: - text: Show v1 access policy {id}. slots: id: path.id - text: Get access policy {id} from the deprecated v1 API. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v1/access-policies/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an access policy (v1) effect: destructive questions: - Can I delete an access policy using the deprecated v1 API? - What happens to workload access when an access policy is deleted? instructions: - text: Delete access policy {id} with the v1 endpoint. slots: id: path.id - text: Remove v1 access policy {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v1/access-policies/{id}'].patch update: x-apievangelist-phrasing: intent: Partially update an access policy (v1) effect: write questions: - Can I swap the credential provider on an existing policy without rebuilding it? - Which parts of an access policy can be patched in v1? instructions: - text: Deactivate v1 access policy {id}. slots: id: path.id - text: Set credential provider {credentialProvider} on access policy {id}. slots: id: path.id credentialProvider: requestBody.credentialProvider - text: Attach access conditions {accessConditions} to policy {id}. slots: id: path.id accessConditions: requestBody.accessConditions method: generated generated: '2026-09-26' - target: $.paths['/api/v1/access-policies/getByWorkloadIds/{clientWorkloadId}/{serverWorkloadId}'].get update: x-apievangelist-phrasing: intent: Find the policy between two workloads (v1) effect: read questions: - Is there an access policy linking this client workload to that server workload? - How do I find the policy for a client and server workload pair in v1? instructions: - text: Find the access policy between client workload {client} and server workload {server}. slots: client: path.clientWorkloadId server: path.serverWorkloadId - text: Look up the v1 policy for client {client} calling server {server}. slots: client: path.clientWorkloadId server: path.serverWorkloadId method: generated generated: '2026-09-26' - target: $.paths['/api/v1/access-policies'].get update: x-apievangelist-phrasing: intent: List access policies (v1) effect: read questions: - Which access policies exist in my tenant according to v1? - Can I filter the v1 access policy list? - How do I page through all access policies with the old API? instructions: - text: List access policies with the v1 API. - text: List v1 access policies matching {filter}. slots: filter: query.filter - text: Show page {page} of v1 access policies. slots: page: query.page method: generated generated: '2026-09-26' - target: $.paths['/api/v1/access-policies'].put update: x-apievangelist-phrasing: intent: Replace an access policy (v1) effect: write questions: - How do I overwrite an access policy's full configuration in v1? - Does a full v1 policy update need both a client and server workload? instructions: - text: Replace access policy {name} so client {client} reaches server {server}. slots: name: requestBody.name client: requestBody.clientWorkload server: requestBody.serverWorkload - text: Fully update v1 policy {name} with credential provider {credentialProvider}. slots: name: requestBody.name credentialProvider: requestBody.credentialProvider method: generated generated: '2026-09-26' - target: $.paths['/api/v1/access-policies'].post update: x-apievangelist-phrasing: intent: Create an access policy (v1) effect: write questions: - How do I let one workload call another with a v1 access policy? - Can I add trust providers and access conditions when creating a v1 policy? instructions: - text: Create v1 access policy {name} from client {client} to server {server}. slots: name: requestBody.name client: requestBody.clientWorkload server: requestBody.serverWorkload - text: Create policy {name} using credential provider {credentialProvider} and trust providers {trustProviders}. slots: name: requestBody.name credentialProvider: requestBody.credentialProvider trustProviders: requestBody.trustProviders method: generated generated: '2026-09-26' - target: $.paths['/api/v1/access-policies/{id}/notes'].post update: x-apievangelist-phrasing: intent: Add a note to an access policy (v1) effect: write questions: - Can I record why an access policy was changed? - How do I leave a note on a policy with the v1 API? instructions: - text: Add the note {note} to access policy {id}. slots: id: path.id note: requestBody.note - text: Annotate v1 policy {id} with {note}. slots: id: path.id note: requestBody.note method: generated generated: '2026-09-26'