# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Aembit Cloud Access Policy v2 API version: 1.0.0 extends: openapi/aembit-access-policy-v2-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/api/v2/access-policies/{id}'].get update: x-apievangelist-phrasing: intent: Get an access policy effect: read questions: - What workloads and providers does one access policy tie together? - Can I fetch a single access policy by ID with the current API? instructions: - text: Show access policy {id}. slots: id: path.id - text: Fetch the configuration of access policy {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an access policy effect: destructive questions: - Can I delete an access policy I no longer use? - Does deleting an access policy stop the client workload's access? instructions: - text: Delete access policy {id}. slots: id: path.id - text: Remove the access policy with ID {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies/{id}'].patch update: x-apievangelist-phrasing: intent: Partially update an access policy effect: write questions: - Can I attach several credential providers to an existing policy? - Is it possible to just disable an access policy? instructions: - text: Disable access policy {id}. slots: id: path.id - text: Set credential providers {credentialProviders} on access policy {id}. slots: id: path.id credentialProviders: requestBody.credentialProviders - text: Change the trust providers on policy {id} to {trustProviders}. slots: id: path.id trustProviders: requestBody.trustProviders method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies/getByWorkloadIds/{clientWorkloadId}/{serverWorkloadId}'].get update: x-apievangelist-phrasing: intent: Find the policy between two workloads effect: read questions: - Which access policy governs traffic from a given client workload to a server workload? - Can I look up a policy by its client and server workload IDs? instructions: - text: Get the access policy for client workload {client} and server workload {server}. slots: client: path.clientWorkloadId server: path.serverWorkloadId - text: Which policy lets {client} call {server}? Look it up. slots: client: path.clientWorkloadId server: path.serverWorkloadId method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies'].get update: x-apievangelist-phrasing: intent: List access policies effect: read questions: - Which access policies are configured right now? - Can I search access policies with a free-text query? - How do I group access policies in the list? instructions: - text: List my access policies. - text: Search access policies for {query}. slots: query: query.query - text: List access policies grouped by {groupBy}. slots: groupBy: query.group-by method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies'].put update: x-apievangelist-phrasing: intent: Replace an access policy effect: write questions: - How do I overwrite an entire access policy definition? - Can a full policy update set multiple credential providers at once? instructions: - text: Replace access policy {name} with credential providers {credentialProviders}. slots: name: requestBody.name credentialProviders: requestBody.credentialProviders - text: Fully update policy {name} in resource set {resourceSet}. slots: name: requestBody.name resourceSet: requestBody.resourceSet method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies'].post update: x-apievangelist-phrasing: intent: Create an access policy effect: write questions: - How do I grant a client workload access to a server workload? - Can I require access conditions when creating a new policy? instructions: - text: Create access policy {name} connecting client {client} to server {server}. slots: name: requestBody.name client: requestBody.clientWorkload server: requestBody.serverWorkload - text: Create a new policy {name} with access conditions {accessConditions}. slots: name: requestBody.name accessConditions: requestBody.accessConditions method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies/{id}/notes'].get update: x-apievangelist-phrasing: intent: Read the notes on an access policy effect: read questions: - What notes have been left on an access policy? - Can I see the history of comments recorded on a policy? instructions: - text: Show the notes on access policy {id}. slots: id: path.id - text: List every note attached to policy {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies/{id}/notes'].post update: x-apievangelist-phrasing: intent: Add a note to an access policy effect: write questions: - How do I document a change on an access policy? - Can I attach a free-text note to a policy? instructions: - text: Add note {note} to access policy {id}. slots: id: path.id note: requestBody.note - text: Write {note} as a note on policy {id}. slots: id: path.id note: requestBody.note method: generated generated: '2026-09-26' - target: $.paths['/api/v2/access-policies/{id}/credential-mappings'].get update: x-apievangelist-phrasing: intent: Get an access policy's credential mappings effect: read questions: - Which credentials does an access policy map to its server workload? - Can I see how credential providers are mapped within one policy? instructions: - text: Show the credential mappings for access policy {id}. slots: id: path.id - text: List credential mappings of policy {id}. slots: id: path.id method: generated generated: '2026-09-26'