# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Rbac API version: 1.0.0 extends: openapi/authentik-rbac-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 22 - target: $.paths['/rbac/initial_permissions/'].get update: x-apievangelist-phrasing: intent: List initial permission sets effect: read questions: - Which initial permission sets are configured for newly created objects? - Can I search initial permissions by name? instructions: - text: List all initial permission sets. - text: Find initial permission sets named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/rbac/initial_permissions/'].post update: x-apievangelist-phrasing: intent: Create an initial permission set effect: write questions: - How do I grant a role permissions automatically on objects a user creates? - What does a new initial permissions entry need besides a role? instructions: - text: Create initial permissions {name} for role {role}. slots: name: requestBody.name role: requestBody.role - text: Set up initial permissions {name} giving role {role} the permissions {permissions}. slots: name: requestBody.name role: requestBody.role permissions: requestBody.permissions method: generated generated: '2026-09-26' - target: $.paths['/rbac/initial_permissions/{id}/'].get update: x-apievangelist-phrasing: intent: Get one initial permission set effect: read questions: - What role and permissions does a specific initial permissions entry grant? - How do I look up one initial permission set by ID? instructions: - text: Show initial permission set {id}. slots: id: path.id - text: Get the role and permissions of initial permissions entry {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/rbac/initial_permissions/{id}/'].put update: x-apievangelist-phrasing: intent: Replace an initial permission set effect: write questions: - How do I fully overwrite an existing initial permissions entry? - Can I reassign an initial permission set to a different role in one full update? instructions: - text: Replace initial permission set {id} with name {name} and role {role}. slots: id: path.id name: requestBody.name role: requestBody.role - text: 'Overwrite initial permissions {id}: name {name}, role {role}, permissions {permissions}.' slots: id: path.id name: requestBody.name role: requestBody.role permissions: requestBody.permissions method: generated generated: '2026-09-26' - target: $.paths['/rbac/initial_permissions/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete an initial permission set effect: destructive questions: - How do I stop auto-granting permissions on new objects by removing an initial permission set? - Can I delete an initial permissions entry? instructions: - text: Delete initial permission set {id}. slots: id: path.id - text: Remove the initial permissions entry {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/rbac/initial_permissions/{id}/'].patch update: x-apievangelist-phrasing: intent: Patch fields of an initial permission set effect: write questions: - Can I change only the permissions list on an initial permission set? - Is there a way to rename an initial permissions entry without resending everything? instructions: - text: Patch initial permission set {id} to grant only {permissions}. slots: id: path.id permissions: requestBody.permissions - text: Rename initial permissions entry {id} to {name}. slots: id: path.id name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/rbac/initial_permissions/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an initial permission set effect: read questions: - Which objects reference a given initial permissions entry? - What depends on this initial permission set before I remove it? instructions: - text: List objects that use initial permission set {id}. slots: id: path.id - text: Show dependents of initial permissions entry {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/rbac/permissions/'].get update: x-apievangelist-phrasing: intent: List available permissions effect: read questions: - Which permissions exist in authentik that I can grant to roles? - Can I filter the permission catalog by app label or model? - What permissions does a particular role currently have? instructions: - text: List all available permissions. - text: Show permissions for app {app_label} and model {model}. slots: app_label: query.content_type__app_label model: query.content_type__model - text: Find the permission with codename {codename}. slots: codename: query.codename method: generated generated: '2026-09-26' - target: $.paths['/rbac/permissions/{id}/'].get update: x-apievangelist-phrasing: intent: Get one permission definition effect: read questions: - What does a single permission with a given ID cover? - How do I look up one permission's codename and model? instructions: - text: Show permission {id}. slots: id: path.id - text: Get the codename and model of permission {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/rbac/permissions/assigned_by_roles/'].get update: x-apievangelist-phrasing: intent: List roles holding permissions on an object effect: read questions: - Which roles have permissions on a specific object? - Who has been granted access to one model instance through roles? instructions: - text: Show which roles hold permissions on model {model}. slots: model: query.model - text: List role permissions on {model} object {object_pk}. slots: model: query.model object_pk: query.object_pk method: generated generated: '2026-09-26' - target: $.paths['/rbac/permissions/assigned_by_roles/{uuid}/assign/'].post update: x-apievangelist-phrasing: intent: Grant permissions to a role effect: write questions: - How do I give a role permissions globally across authentik? - Can I grant a role permissions on just one specific object? instructions: - text: Grant role {uuid} the permissions {permissions} globally. slots: uuid: path.uuid permissions: requestBody.permissions - text: Assign {permissions} to role {uuid} only on {model} object {object_pk}. slots: uuid: path.uuid permissions: requestBody.permissions model: requestBody.model object_pk: requestBody.object_pk method: generated generated: '2026-09-26' - target: $.paths['/rbac/permissions/assigned_by_roles/{uuid}/unassign/'].patch update: x-apievangelist-phrasing: intent: Revoke permissions from a role effect: destructive questions: - How do I take permissions away from a role? - Can I revoke a role's permissions on one object while keeping its global ones? instructions: - text: Revoke {permissions} from role {uuid}. slots: uuid: path.uuid permissions: requestBody.permissions - text: Unassign {permissions} from role {uuid} for {model} object {object_pk}. slots: uuid: path.uuid permissions: requestBody.permissions model: requestBody.model object_pk: requestBody.object_pk method: generated generated: '2026-09-26' - target: $.paths['/rbac/permissions/roles/'].get update: x-apievangelist-phrasing: intent: List a role's object permissions effect: read questions: - What object-level permissions has a given role been assigned? - Can I see every per-object grant a role holds? instructions: - text: Show the object permissions assigned to role {uuid}. slots: uuid: query.uuid - text: List per-object grants for role {uuid} matching {search}. slots: uuid: query.uuid search: query.search method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/'].get update: x-apievangelist-phrasing: intent: List roles effect: read questions: - What roles are defined in authentik? - Which roles does a given user have, including inherited ones? - Can I list only the managed roles? instructions: - text: List all roles. - text: 'Show roles for user {users}, including inherited: {inherited}.' slots: users: query.users inherited: query.inherited - text: Find roles assigned to group {groups}. slots: groups: query.groups method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/'].post update: x-apievangelist-phrasing: intent: Create a role effect: write questions: - How do I create a new role for grouping permissions? - What is needed to add a role in authentik? instructions: - text: Create a role named {name}. slots: name: requestBody.name - text: Add a new RBAC role called {name}. slots: name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/{uuid}/'].get update: x-apievangelist-phrasing: intent: Get one role effect: read questions: - What are the details of a specific role? - How do I look up a role by its UUID? instructions: - text: Show role {uuid}. slots: uuid: path.uuid - text: Get the details of RBAC role {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/{uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a role effect: write questions: - How do I do a full update of a role's definition? - Can I overwrite a role record with a PUT? instructions: - text: Replace role {uuid} with name {name}. slots: uuid: path.uuid name: requestBody.name - text: Fully update RBAC role {uuid}, setting its name to {name}. slots: uuid: path.uuid name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/{uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a role effect: destructive questions: - How do I delete a role I no longer need? - Can I remove an RBAC role permanently? instructions: - text: Delete role {uuid}. slots: uuid: path.uuid - text: Permanently remove RBAC role {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/{uuid}/'].patch update: x-apievangelist-phrasing: intent: Rename a role effect: write questions: - Can I just rename a role without a full update? - Is there a patch call to change a role's name? instructions: - text: Rename role {uuid} to {name}. slots: uuid: path.uuid name: requestBody.name - text: Patch RBAC role {uuid} so it is called {name}. slots: uuid: path.uuid name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/{uuid}/add_user/'].post update: x-apievangelist-phrasing: intent: Add a user to a role effect: write questions: - How do I put a user into a role? - Can I assign a role directly to one user? instructions: - text: Add user {pk} to role {uuid}. slots: pk: requestBody.pk uuid: path.uuid - text: Give user {pk} the role {uuid}. slots: pk: requestBody.pk uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/{uuid}/remove_user/'].post update: x-apievangelist-phrasing: intent: Remove a user from a role effect: destructive questions: - How do I take a user out of a role? - Can I revoke a role from one specific user? instructions: - text: Remove user {pk} from role {uuid}. slots: pk: requestBody.pk uuid: path.uuid - text: Revoke role {uuid} from user {pk}. slots: pk: requestBody.pk uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/rbac/roles/{uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a role effect: read questions: - Which objects reference a given role? - What depends on this role before I delete it? instructions: - text: List everything that uses role {uuid}. slots: uuid: path.uuid - text: Show dependents of RBAC role {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26'