# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.Governance Identity Governance.entitlement… version: 1.0.0 extends: openapi/azure-ad-identitygovernance-entitlementmanagement-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 1265 - target: $.paths['/identityGovernance/entitlementManagement'].get update: x-apievangelist-phrasing: intent: Read the entitlement management container effect: read questions: - What does the entitlement management root object in Microsoft Entra identity governance contain? - Can I expand the top-level entitlement management node to see its catalogs and access packages together? instructions: - text: Fetch the entitlement management root for my tenant. - text: Show the top-level entitlement management object with its settings expanded. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement'].delete update: x-apievangelist-phrasing: intent: Delete the entitlement management container effect: destructive questions: - Is it possible to remove the whole entitlement management navigation property from identity governance? - What happens if I delete the entitlement management root node itself? instructions: - text: Delete the entitlement management container from identity governance. - text: Remove the top-level entitlement management node entirely. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement'].patch update: x-apievangelist-phrasing: intent: Update the entitlement management container effect: write questions: - Can I patch the entitlement management root object directly? - Which top-level entitlement management properties, like its settings, can be changed in one update? instructions: - text: Patch the entitlement management root with new settings {settings}. slots: settings: requestBody.settings - text: Update the top-level entitlement management object in identity governance. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals'].get update: x-apievangelist-phrasing: intent: List access package assignment approvals effect: read questions: - Which access package assignment approvals exist in entitlement management? - Can I page through every assignment approval record with a filter? instructions: - text: List all access package assignment approvals. - text: Show the assignment approvals, newest first, top 20. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals'].post update: x-apievangelist-phrasing: intent: Create an assignment approval record effect: write questions: - Can I add a new approval object under access package assignment approvals? - What fields, like stages, go into a newly created assignment approval? instructions: - text: Create an assignment approval with stages {stages}. slots: stages: requestBody.stages - text: Add a new access package assignment approval record. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}'].get update: x-apievangelist-phrasing: intent: Get an assignment approval by ID effect: read questions: - How do I look up one approval using the ID of an access package assignment request? - What properties does a single assignment approval object expose? instructions: - text: Get approval {approval} for the access package request. slots: approval: path.approval-id - text: Show me the details of assignment approval {approval}. slots: approval: path.approval-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}'].delete update: x-apievangelist-phrasing: intent: Delete an assignment approval effect: destructive questions: - Can an access package assignment approval object be deleted? - What is removed when I delete one assignment approval entry? instructions: - text: Delete assignment approval {approval}. slots: approval: path.approval-id - text: Remove the approval record {approval} from entitlement management. slots: approval: path.approval-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}'].patch update: x-apievangelist-phrasing: intent: Update an assignment approval effect: write questions: - Can I patch an existing assignment approval object, for example its stages? - Is it possible to overwrite the stages list on one approval record? instructions: - text: Update approval {approval} with stages {stages}. slots: approval: path.approval-id stages: requestBody.stages - text: Patch assignment approval {approval}. slots: approval: path.approval-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}/stages'].get update: x-apievangelist-phrasing: intent: List the stages of an approval effect: read questions: - Which approval stages belong to a given access package approval? - How can an approver see every stage in a multi-stage approval? instructions: - text: List the stages of approval {approval}. slots: approval: path.approval-id - text: Show all approval stages for request approval {approval}. slots: approval: path.approval-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}/stages'].post update: x-apievangelist-phrasing: intent: Add a stage to an approval effect: write questions: - Can I add another stage object to an existing approval? - What does a new approval stage need, such as a display name or status? instructions: - text: Add a stage named {name} to approval {approval}. slots: name: requestBody.displayName approval: path.approval-id - text: Create a new stage on approval {approval} with status {status}. slots: approval: path.approval-id status: requestBody.status method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}/stages/{approvalStage-id}'].get update: x-apievangelist-phrasing: intent: Get one stage of an approval effect: read questions: - How do I check who reviewed a specific stage of an approval and when? - What does a single approval stage record show about its review result? instructions: - text: Get stage {stage} of approval {approval}. slots: stage: path.approvalStage-id approval: path.approval-id - text: Show the reviewer and result for approval stage {stage} in approval {approval}. slots: stage: path.approvalStage-id approval: path.approval-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}/stages/{approvalStage-id}'].delete update: x-apievangelist-phrasing: intent: Delete a stage from an approval effect: destructive questions: - Can one stage be removed from an approval object? - What happens to an approval when I delete one of its stages? instructions: - text: Delete stage {stage} from approval {approval}. slots: stage: path.approvalStage-id approval: path.approval-id - text: Remove approval stage {stage} under approval {approval}. slots: stage: path.approvalStage-id approval: path.approval-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}/stages/{approvalStage-id}'].patch update: x-apievangelist-phrasing: intent: Approve or deny an approval stage effect: write questions: - How do I approve or deny an access package request as an approver? - Do I have to give a justification when I deny a stage of an approval? - Which review results can I record on an approval stage? instructions: - text: Approve stage {stage} of approval {approval} with justification {justification}. slots: stage: path.approvalStage-id approval: path.approval-id justification: requestBody.justification - text: Set the review result on stage {stage} of approval {approval} to {result}. slots: stage: path.approvalStage-id approval: path.approval-id result: requestBody.reviewResult - text: Deny approval stage {stage} in {approval} because {justification}. slots: stage: path.approvalStage-id approval: path.approval-id justification: requestBody.justification method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/{approval-id}/stages/$count'].get update: x-apievangelist-phrasing: intent: Count the stages of an approval effect: read questions: - How many stages does a particular approval have? - Can I get just the number of approval stages without listing them? instructions: - text: Count the stages in approval {approval}. slots: approval: path.approval-id - text: Tell me how many stages approval {approval} has. slots: approval: path.approval-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/$count'].get update: x-apievangelist-phrasing: intent: Count access package assignment approvals effect: read questions: - How many access package assignment approvals are there in total? - Is there a quick way to get the total number of assignment approval records? instructions: - text: Count all access package assignment approvals. - text: Give me the total number of assignment approval objects. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageAssignmentApprovals/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get update: x-apievangelist-phrasing: intent: List approvals awaiting my decision effect: read questions: - Which access package requests are waiting for me to approve? - Can I see only the approvals that are in scope for me as the signed-in approver? instructions: - text: List the approvals where I am the {on}. slots: 'on': path.on - text: Show assignment approvals filtered to the current user as {on}. slots: 'on': path.on method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages'].get update: x-apievangelist-phrasing: intent: List access packages effect: read questions: - What access packages have been set up in my Entra tenant? - Can I filter the access package list by display name or catalog? - Does the access package list include hidden packages too? instructions: - text: List all access packages in entitlement management. - text: Show access packages whose name contains Marketing. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages'].post update: x-apievangelist-phrasing: intent: Create an access package effect: write questions: - How do I create a new access package in an existing catalog? - Can a new access package be hidden from requestors when I create it? instructions: - text: Create an access package called {name} in catalog {catalog}. slots: name: requestBody.displayName catalog: requestBody.catalog - text: Create access package {name} with description {description} in catalog {catalog}. slots: name: requestBody.displayName description: requestBody.description catalog: requestBody.catalog - text: Create a hidden access package {name}, setting isHidden to {isHidden}. slots: name: requestBody.displayName isHidden: requestBody.isHidden method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}'].get update: x-apievangelist-phrasing: intent: Get an access package effect: read questions: - Where can I read the properties and relationships of a single access package? - Can I expand an access package to include its resource role scopes? instructions: - text: Get access package {package}. slots: package: path.accessPackage-id - text: Show access package {package} with its resource role scopes expanded. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}'].delete update: x-apievangelist-phrasing: intent: Delete an access package effect: destructive questions: - Can I delete an access package that still has users assigned? - What must be removed before an access package can be deleted? instructions: - text: Delete access package {package}. slots: package: path.accessPackage-id - text: Remove the access package {package} permanently. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}'].patch update: x-apievangelist-phrasing: intent: Update an access package effect: write questions: - How do I rename an access package or change its description? - Can I hide an existing access package from the request portal? instructions: - text: Rename access package {package} to {name}. slots: package: path.accessPackage-id name: requestBody.displayName - text: Change the description of access package {package} to {description}. slots: package: path.accessPackage-id description: requestBody.description - text: Set isHidden to {isHidden} on access package {package}. slots: isHidden: requestBody.isHidden package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/accessPackagesIncompatibleWith'].get update: x-apievangelist-phrasing: intent: List packages that mark this one incompatible effect: read questions: - Which other access packages have marked this package as incompatible with them? - What packages consider mine a conflict, looking from the other side? instructions: - text: List the access packages that declare {package} incompatible with them. slots: package: path.accessPackage-id - text: Show packages that flag access package {package} as a conflict. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/accessPackagesIncompatibleWith/{accessPackage-id1}'].get update: x-apievangelist-phrasing: intent: Get a package that marks this one incompatible effect: read questions: - Can I read one specific package from the set that treats mine as incompatible? - What does a single conflicting package look like from the incompatible-with side? instructions: - text: Get package {other} from the packages that list {package} as incompatible with them. slots: other: path.accessPackage-id1 package: path.accessPackage-id - text: Show details of {other}, which marks access package {package} as a conflict. slots: other: path.accessPackage-id1 package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/accessPackagesIncompatibleWith/$count'].get update: x-apievangelist-phrasing: intent: Count packages that mark this one incompatible effect: read questions: - How many access packages have flagged this package as incompatible with them? - Can I get only the number of packages that treat mine as a conflict? instructions: - text: Count the packages that mark access package {package} as incompatible with them. slots: package: path.accessPackage-id - text: Tell me how many packages flag {package} as a conflict from their side. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies'].get update: x-apievangelist-phrasing: intent: List an access package's assignment policies effect: read questions: - Which assignment policies are attached to this access package? - Can I see who is allowed to request a package by reading its policies? instructions: - text: List the assignment policies of access package {package}. slots: package: path.accessPackage-id - text: Show every policy on access package {package}. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies'].post update: x-apievangelist-phrasing: intent: Add an assignment policy to an access package effect: write questions: - Can I create an assignment policy directly under a specific access package? - What settings, such as target scope and expiration, go into a package's new policy? instructions: - text: Add a policy named {name} to access package {package}. slots: name: requestBody.displayName package: path.accessPackage-id - text: Create a policy on package {package} with target scope {targetScope} and expiration {expiration}. slots: package: path.accessPackage-id targetScope: requestBody.allowedTargetScope expiration: requestBody.expiration method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}'].get update: x-apievangelist-phrasing: intent: Get one policy of an access package effect: read questions: - How do I read a particular assignment policy through its access package? - What approval and requestor settings does one package policy have? instructions: - text: Get policy {policy} of access package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show the requestor settings of policy {policy} under package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}'].delete update: x-apievangelist-phrasing: intent: Remove a policy from an access package effect: destructive questions: - Can I delete one assignment policy through its parent access package? - What happens to requests when a package policy is deleted? instructions: - text: Delete policy {policy} from access package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Remove assignment policy {policy} under package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}'].patch update: x-apievangelist-phrasing: intent: Update a policy through its access package effect: write questions: - Can I patch an assignment policy by addressing it under its access package? - Which policy fields, such as display name or expiration, can I change here? instructions: - text: Rename policy {policy} on access package {package} to {name}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id name: requestBody.displayName - text: Update the expiration of policy {policy} in package {package} to {expiration}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id expiration: requestBody.expiration method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/accessPackage'].get update: x-apievangelist-phrasing: intent: Get the package that owns a package policy effect: read questions: - From a policy nested under an access package, can I navigate back to the owning package? - Which access package contains this particular nested policy? instructions: - text: Get the access package that contains policy {policy} under {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show the owning package for nested policy {policy} of {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/catalog'].get update: x-apievangelist-phrasing: intent: Get the catalog of a package policy effect: read questions: - Which catalog does the package behind this nested policy belong to? - Can I read the catalog straight from a policy under an access package? instructions: - text: Get the catalog for policy {policy} of access package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show which catalog holds nested policy {policy} in package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings'].get update: x-apievangelist-phrasing: intent: List custom extension stages on a package policy effect: read questions: - At which request stages does this package policy run custom workflow extensions? - Can I list the Logic App extension stage settings for a policy under an access package? instructions: - text: List custom extension stage settings of policy {policy} in package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show when policy {policy} under {package} triggers custom extensions. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings'].post update: x-apievangelist-phrasing: intent: Add a custom extension stage to a package policy effect: write questions: - How do I make a policy under an access package call a custom extension at a given stage? - Can I attach a workflow extension to the assignment-granted stage of a package's policy? instructions: - text: Add custom extension {extension} at stage {trigger} to policy {policy} of package {package}. slots: extension: requestBody.customExtension trigger: requestBody.stage policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Create an extension stage setting on policy {policy} in {package} for stage {trigger}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id trigger: requestBody.stage method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}'].get update: x-apievangelist-phrasing: intent: Get a custom extension stage on a package policy effect: read questions: - What stage does one custom extension setting on a package policy fire at? - Can I read a single extension stage setting nested under a package's policy? instructions: - text: Get extension stage setting {setting} of policy {policy} in package {package}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show custom extension stage {setting} on package {package} policy {policy}. slots: setting: path.customExtensionStageSetting-id package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}'].delete update: x-apievangelist-phrasing: intent: Remove a custom extension stage from a package policy effect: destructive questions: - Can I stop a package policy from calling a custom extension at some stage? - Is deleting an extension stage setting under a package policy reversible? instructions: - text: Delete extension stage setting {setting} from policy {policy} of package {package}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Remove custom extension stage {setting} on {package} policy {policy}. slots: setting: path.customExtensionStageSetting-id package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}'].patch update: x-apievangelist-phrasing: intent: Update a custom extension stage on a package policy effect: write questions: - Can I change which stage a custom extension runs at on a package policy? - Is it possible to swap the custom extension linked to a stage setting under a package? instructions: - text: Change setting {setting} on policy {policy} of package {package} to run at stage {trigger}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id trigger: requestBody.stage - text: Point extension stage setting {setting} of {package} policy {policy} at extension {extension}. slots: setting: path.customExtensionStageSetting-id package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id extension: requestBody.customExtension method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}/customExtension'].get update: x-apievangelist-phrasing: intent: Get the extension a package policy stage runs effect: read questions: - Which custom workflow extension gets executed at this stage of a package policy? - Can I read the Logic App details behind a package policy's extension stage? instructions: - text: Get the custom extension run by stage setting {setting} of policy {policy} in {package}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show which workflow extension setting {setting} calls for package {package} policy {policy}. slots: setting: path.customExtensionStageSetting-id package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/$count'].get update: x-apievangelist-phrasing: intent: Count custom extension stages on a package policy effect: read questions: - How many custom extension stage settings does a policy under an access package have? - Can I get just the number of extension triggers on a package policy? instructions: - text: Count the custom extension stage settings of policy {policy} in package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Tell me how many extension triggers policy {policy} of {package} has. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions'].get update: x-apievangelist-phrasing: intent: List requestor questions on a package policy effect: read questions: - What questions are requestors asked when they request through this package policy? - Can I see the question order for a policy nested under an access package? instructions: - text: List the requestor questions on policy {policy} of package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show the questions asked by policy {policy} in access package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions'].post update: x-apievangelist-phrasing: intent: Add a requestor question to a package policy effect: write questions: - How do I add a question requestors must answer to a policy under an access package? - Can I make a new policy question required and set its position? instructions: - text: Add question {text} to policy {policy} of package {package}. slots: text: requestBody.text policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Create a question {text} at position {sequence} on package {package} policy {policy}. slots: text: requestBody.text sequence: requestBody.sequence package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/{accessPackageQuestion-id}'].get update: x-apievangelist-phrasing: intent: Get a requestor question on a package policy effect: read questions: - Can I read one requestor question from a policy under an access package? - Is a given question on a package policy required and editable? instructions: - text: Get question {question} of policy {policy} in package {package}. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Show whether question {question} on {package} policy {policy} is required. slots: question: path.accessPackageQuestion-id package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/{accessPackageQuestion-id}'].delete update: x-apievangelist-phrasing: intent: Remove a requestor question from a package policy effect: destructive questions: - Can I drop a question that requestors see on a package policy? - What happens to earlier answers if a package policy question is deleted? instructions: - text: Delete question {question} from policy {policy} of package {package}. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Remove requestor question {question} on {package} policy {policy}. slots: question: path.accessPackageQuestion-id package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/{accessPackageQuestion-id}'].patch update: x-apievangelist-phrasing: intent: Edit a requestor question on a package policy effect: write questions: - Can I reword a question or change its order on a package policy? - Is it possible to make an existing package policy question optional? instructions: - text: Change the text of question {question} on policy {policy} of package {package} to {text}. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id text: requestBody.text - text: Move question {question} on {package} policy {policy} to position {sequence}. slots: question: path.accessPackageQuestion-id package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id sequence: requestBody.sequence method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/$count'].get update: x-apievangelist-phrasing: intent: Count requestor questions on a package policy effect: read questions: - How many questions does a policy under this access package ask? - Can I get only the number of requestor questions on a package policy? instructions: - text: Count the questions on policy {policy} of access package {package}. slots: policy: path.accessPackageAssignmentPolicy-id package: path.accessPackage-id - text: Tell me how many requestor questions {package} policy {policy} has. slots: package: path.accessPackage-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/assignmentPolicies/$count'].get update: x-apievangelist-phrasing: intent: Count an access package's policies effect: read questions: - How many assignment policies does this access package have? - Can I get just the number of policies attached to one package? instructions: - text: Count the assignment policies on access package {package}. slots: package: path.accessPackage-id - text: Tell me how many policies package {package} carries. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/catalog'].get update: x-apievangelist-phrasing: intent: Get the catalog of an access package effect: read questions: - Which catalog does this access package live in? - Can I read the catalog details straight from an access package? instructions: - text: Get the catalog of access package {package}. slots: package: path.accessPackage-id - text: Show which catalog holds package {package}. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleAccessPackages'].get update: x-apievangelist-phrasing: intent: List packages marked incompatible with this one effect: read questions: - Which access packages have I marked as incompatible on this package? - Can a user who holds one of these conflicting packages still request mine? instructions: - text: List the access packages marked incompatible on package {package}. slots: package: path.accessPackage-id - text: Show the conflicting packages configured on {package}. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleAccessPackages/{accessPackage-id1}/$ref'].delete update: x-apievangelist-phrasing: intent: Unmark one package as incompatible (by path) effect: destructive questions: - Can I remove a single package from my incompatible list by putting its ID in the URL? - How is an incompatibility link removed when I address the other package by path? instructions: - text: Remove {other} from the incompatible packages of {package}, addressing it in the path. slots: other: path.accessPackage-id1 package: path.accessPackage-id - text: Unlink incompatible package {other} from access package {package} by its path ID. slots: other: path.accessPackage-id1 package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleAccessPackages/$count'].get update: x-apievangelist-phrasing: intent: Count packages marked incompatible effect: read questions: - How many incompatible access packages are configured on this package? - Can I get only the number of packages marked as a conflict on mine? instructions: - text: Count the packages marked incompatible on access package {package}. slots: package: path.accessPackage-id - text: Tell me how many conflicting packages {package} has configured. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleAccessPackages/$ref'].get update: x-apievangelist-phrasing: intent: List references to incompatible packages effect: read questions: - Can I get only the reference links of the packages marked incompatible, not full objects? - What odata IDs point to the packages flagged as incompatible on mine? instructions: - text: List the reference links of incompatible packages on {package}. slots: package: path.accessPackage-id - text: Show only the odata IDs of conflicting packages for access package {package}. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleAccessPackages/$ref'].post update: x-apievangelist-phrasing: intent: Mark a package as incompatible effect: write questions: - How do I stop users with one access package from requesting another? - Can I add a package to the incompatible list by its odata reference? instructions: - text: Mark package {ref} as incompatible with access package {package}. slots: ref: requestBody.@odata.id package: path.accessPackage-id - text: Add incompatible package reference {ref} to package {package}. slots: ref: requestBody.@odata.id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleAccessPackages/$ref'].delete update: x-apievangelist-phrasing: intent: Unmark a package as incompatible (by query) effect: destructive questions: - Can I remove an incompatible package by passing its reference in the @id query parameter? - How do I undo a package conflict using the collection-level reference endpoint? instructions: - text: Remove incompatible package {refId} from {package} using the @id query reference. slots: refId: query.@id package: path.accessPackage-id - text: Unmark the conflict between {package} and the package referenced by {refId}. slots: package: path.accessPackage-id refId: query.@id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups'].get update: x-apievangelist-phrasing: intent: List groups marked incompatible effect: read questions: - Which groups are marked as incompatible with this access package? - Can members of certain groups be blocked from requesting a package? instructions: - text: List the groups marked incompatible on access package {package}. slots: package: path.accessPackage-id - text: Show the conflicting groups set on {package}. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups/{group-id}/$ref'].delete update: x-apievangelist-phrasing: intent: Unmark a group as incompatible (by path) effect: destructive questions: - Can I remove one incompatible group by putting the group ID in the URL? - How do I let a group's members request a package again, addressing the group by path? instructions: - text: Remove group {group} from the incompatible groups of package {package}. slots: group: path.group-id package: path.accessPackage-id - text: Unlink incompatible group {group} from {package} by its path ID. slots: group: path.group-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups/{group-id}/serviceProvisioningErrors'].get update: x-apievangelist-phrasing: intent: List provisioning errors of an incompatible group effect: read questions: - Does an incompatible group have any service provisioning errors? - Can I filter a conflicting group's provisioning errors to unresolved ones? instructions: - text: List service provisioning errors for incompatible group {group} on package {package}. slots: group: path.group-id package: path.accessPackage-id - text: Show unresolved provisioning errors of group {group} blocked by {package}. slots: group: path.group-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups/{group-id}/serviceProvisioningErrors/$count'].get update: x-apievangelist-phrasing: intent: Count provisioning errors of an incompatible group effect: read questions: - How many provisioning errors does a group marked incompatible on a package have? - Can I just get the error count for a conflicting group? instructions: - text: Count provisioning errors of incompatible group {group} on package {package}. slots: group: path.group-id package: path.accessPackage-id - text: Tell me how many service errors group {group} has under {package}. slots: group: path.group-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups/$count'].get update: x-apievangelist-phrasing: intent: Count groups marked incompatible effect: read questions: - How many groups are flagged as incompatible with this access package? - Can I get only the number of conflicting groups on a package? instructions: - text: Count the incompatible groups on access package {package}. slots: package: path.accessPackage-id - text: Tell me how many conflicting groups {package} has. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups/$ref'].get update: x-apievangelist-phrasing: intent: List references to incompatible groups effect: read questions: - Can I retrieve just the reference links of the incompatible groups on a package? - Which group odata IDs are recorded as conflicts on my package? instructions: - text: List the reference links of incompatible groups on {package}. slots: package: path.accessPackage-id - text: Show only the group odata IDs flagged as conflicts on access package {package}. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups/$ref'].post update: x-apievangelist-phrasing: intent: Mark a group as incompatible effect: write questions: - How do I block members of a group from requesting an access package? - Can I add a group to a package's incompatible list by odata reference? instructions: - text: Block members of group {ref} from requesting access package {package}. slots: ref: requestBody.@odata.id package: path.accessPackage-id - text: Add incompatible group reference {ref} to package {package}. slots: ref: requestBody.@odata.id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/incompatibleGroups/$ref'].delete update: x-apievangelist-phrasing: intent: Unmark a group as incompatible (by query) effect: destructive questions: - Can I remove an incompatible group by giving its reference in the @id query parameter? - How do I clear a group conflict through the collection-level reference endpoint? instructions: - text: Remove incompatible group {refId} from {package} using the @id query reference. slots: refId: query.@id package: path.accessPackage-id - text: Unmark the group conflict referenced by {refId} on access package {package}. slots: refId: query.@id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/microsoft.graph.getApplicablePolicyRequirements'].post update: x-apievangelist-phrasing: intent: Get my request requirements for a package effect: read questions: - What do I need to provide before I can request this access package? - Which of a package's policies am I, the signed-in user, allowed to request under? instructions: - text: Get the policy requirements that apply to me for access package {package}. slots: package: path.accessPackage-id - text: Show what I must answer or justify to request package {package}. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes'].get update: x-apievangelist-phrasing: intent: List the resource roles granted by a package effect: read questions: - Which groups, apps or SharePoint sites and roles does this access package grant? - Can I see every resource role and scope bundled into one package? instructions: - text: List the resource grants in access package {package}. slots: package: path.accessPackage-id - text: Show which resource roles and scopes package {package} hands out. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes'].post update: x-apievangelist-phrasing: intent: Add a resource role to an access package effect: write questions: - How do I add a group membership or app role to an access package? - Does the resource have to be in the catalog before I add its role to a package? instructions: - text: Add resource role {roleBody} with scope {scopeBody} to access package {package}. slots: roleBody: requestBody.role scopeBody: requestBody.scope package: path.accessPackage-id - text: Grant the resource role {roleBody} through package {package}. slots: roleBody: requestBody.role package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}'].get update: x-apievangelist-phrasing: intent: Get one resource grant of a package effect: read questions: - Can I read a single resource role and scope pairing inside an access package? - Which role and scope does one of a package's resource grants point to? instructions: - text: Get resource grant {grant} of access package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show the role and scope behind grant {grant} in package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}'].delete update: x-apievangelist-phrasing: intent: Remove a resource role from an access package effect: destructive questions: - How do I stop an access package from granting a particular resource role? - What happens to existing assignees when a resource role is removed from a package? instructions: - text: Remove resource grant {grant} from access package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Delete the role-and-scope pairing {grant} in package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource grant in a package effect: write questions: - Can I change the role or scope of an existing resource grant in a package? - Is it possible to patch a resource role scope rather than recreate it? instructions: - text: Change grant {grant} in package {package} to use role {roleBody}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id roleBody: requestBody.role - text: Update the scope of resource grant {grant} in {package} to {scopeBody}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id scopeBody: requestBody.scope method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role'].get update: x-apievangelist-phrasing: intent: Get the role a resource grant hands out effect: read questions: - Which role does this resource grant in my access package hand out? - Can I see the origin ID of the role a package grant assigns? instructions: - text: Get the role handed out by grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show which role resource grant {grant} of package {package} assigns. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role'].delete update: x-apievangelist-phrasing: intent: Unlink the role from a resource grant effect: destructive questions: - Can I unlink the role from a package's resource grant? - What does clearing a grant's role navigation remove? instructions: - text: Unlink the role from grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Clear the assigned role on resource grant {grant} of package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role'].patch update: x-apievangelist-phrasing: intent: Update the role a resource grant assigns effect: write questions: - Can I rename the role a resource grant assigns? - Which role properties, like origin ID, are editable through a grant? instructions: - text: Rename the role assigned by grant {grant} in {package} to {name}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Set origin ID {originId} on the role of resource grant {grant}, package {package}. slots: originId: requestBody.originId grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource'].get update: x-apievangelist-phrasing: intent: Get the resource that owns a grant's role effect: read questions: - Which app, group or site owns the role in this package grant? - Can I read the origin system of the role-owning resource? instructions: - text: Get the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show which application owns the role of grant {grant}, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource that owns a grant's role effect: destructive questions: - Can I unlink the role-owning resource from a grant's role? - What is lost if a grant role's owning resource link is deleted? instructions: - text: Unlink the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Delete the owning resource link beneath grant {grant}'s role, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource that owns a grant's role effect: write questions: - Can I edit the display name of the role-owning resource? - Which attributes of a grant role's owning resource are patchable? instructions: - text: Rename the role-owning resource for grant {grant} in {package} to {name}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Change the role-owning resource description on grant {grant}, package {package}, to {description}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a grant role's owner effect: read questions: - Which environment is the role-owning resource hosted in? - Can I read hosting environment details for a grant role's owner? instructions: - text: Get the environment of the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show where grant {grant}'s role-owning resource lives, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource that owns a grant's role effect: write questions: - Can I trigger a re-sync of the role-owning resource behind a grant? - How do I pull newly added roles from the resource that owns a grant's role? instructions: - text: Refresh the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Re-sync the owner of grant {grant}'s role in package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles offered by a grant role's owner effect: read questions: - What roles does the role-owning resource offer besides the granted one? - Can I list all roles offered by the resource behind a grant's role? instructions: - text: List roles offered by the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every role the owner of grant {grant}'s role offers, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a grant role's owner effect: write questions: - Can I add a new role offered by the role-owning resource? - Does a new role on the grant role's owner need an origin ID? instructions: - text: Add role {name} offered by the role-owning resource for grant {grant} in {package}. slots: name: requestBody.displayName grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Create a role with origin ID {originId} on grant {grant}'s role owner, package {package}. slots: originId: requestBody.originId grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role offered by a grant role's owner effect: read questions: - Can I read one role offered by the role-owning resource of a grant? - Where does a specific role on a grant role's owner originate? instructions: - text: Get role {role} offered by the role-owning resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show role {role} from the owner of grant {grant}'s role, package {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role offered by a grant role's owner effect: destructive questions: - Can I delete one role offered by the role-owning resource? - What breaks if a role on the grant role's owner is removed? instructions: - text: Delete role {role} offered by the role-owning resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Remove role {role} permanently from the owner of grant {grant}'s role, package {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role offered by a grant role's owner effect: write questions: - Can I rename a role offered by the role-owning resource? - Which fields of a role on a grant role's owner can change? instructions: - text: Rename role {role} offered by the role-owning resource for grant {grant} in {package} to {name}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Update role {role}'s description to {description} on the owner of grant {grant}'s role, package {package}. slots: role: path.accessPackageResourceRole-id description: requestBody.description grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles offered by a grant role's owner effect: read questions: - How many roles does the role-owning resource of a grant offer? - Is there a quick count of roles on a grant role's owner? instructions: - text: Count roles offered by the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me the number of roles grant {grant}'s role owner has, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes within a grant role's owner effect: read questions: - Which scopes exist within the role-owning resource of a grant? - Does the resource owning a grant's role have a root scope? instructions: - text: List scopes within the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every scope inside grant {grant}'s role owner, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope within a grant role's owner effect: write questions: - Can I add a scope within the role-owning resource? - How do I flag a new scope inside a grant role's owner as root? instructions: - text: Add scope {name} within the role-owning resource for grant {grant} in {package}. slots: name: requestBody.displayName grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Create a scope inside grant {grant}'s role owner with isRootScope {isRootScope}, package {package}. slots: grant: path.accessPackageResourceRoleScope-id isRootScope: requestBody.isRootScope package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope within a grant role's owner effect: read questions: - Can I read one scope within the role-owning resource? - Is a given scope inside a grant role's owner the root scope? instructions: - text: Get scope {scope} within the role-owning resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Display the details of scope {scope} inside grant {grant}'s role owner, package {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope within a grant role's owner effect: destructive questions: - Can I delete a scope within the role-owning resource? - What happens when a scope inside a grant role's owner is removed? instructions: - text: Delete scope {scope} within the role-owning resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Remove scope {scope} from inside grant {grant}'s role owner, package {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope within a grant role's owner effect: write questions: - Can I rename a scope within the role-owning resource? - Which scope fields inside a grant role's owner are patchable? instructions: - text: Rename scope {scope} within the role-owning resource for grant {grant} in {package} to {name}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Update scope {scope}'s description to {description} inside grant {grant}'s role owner, package {package}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource of a catalogued scope effect: read questions: - Which resource does a catalogued scope under a grant role's owner belong to? - Can I navigate from a catalogued scope back to its resource on the role-owning branch? instructions: - text: Get the resource of catalogued scope {scope} for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show which resource catalogued scope {scope} belongs to, role-owning branch of grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a catalogued scope effect: destructive questions: - Can I unlink the resource from a catalogued scope on the role-owning branch? - What gets removed when a catalogued scope's resource link is deleted? instructions: - text: Unlink the resource of catalogued scope {scope} for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Delete catalogued scope {scope}'s resource link, role-owning branch of grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource of a catalogued scope effect: write questions: - Can I rename the resource behind a catalogued scope on the role-owning branch? - Which fields of a catalogued scope's resource can be patched? instructions: - text: Rename the resource of catalogued scope {scope} for grant {grant} in {package} to {name}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Set the description of catalogued scope {scope}'s resource to {description}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a catalogued scope's resource effect: read questions: - Where is a catalogued scope's resource hosted, on the role-owning branch? - Can I get environment info for the resource of a catalogued scope? instructions: - text: Get the environment of catalogued scope {scope}'s resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show hosting environment details for the resource of catalogued scope {scope}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a catalogued scope's resource effect: write questions: - Can I re-sync the resource of a catalogued scope on the role-owning branch? - How do I refresh a catalogued scope's resource so new roles appear? instructions: - text: Refresh catalogued scope {scope}'s resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Re-sync the resource behind catalogued scope {scope}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles on a catalogued scope's resource effect: read questions: - Which roles are offered by a catalogued scope's resource? - Can I list roles for the resource of a catalogued scope on the role-owning branch? instructions: - text: List roles offered by catalogued scope {scope}'s resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show all roles on the resource of catalogued scope {scope}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a catalogued scope's resource effect: write questions: - Can I add a role offered by a catalogued scope's resource? - What does a new role on a catalogued scope's resource need? instructions: - text: Add role {name} offered by catalogued scope {scope}'s resource for grant {grant} in {package}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Create a role with origin ID {originId} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: originId: requestBody.originId scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role on a catalogued scope's resource effect: read questions: - Can I read one role offered by a catalogued scope's resource? - Where does a role on a catalogued scope's resource originate? instructions: - text: Get role {role} offered by catalogued scope {scope}'s resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show role {role} on the resource of catalogued scope {scope}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role on a catalogued scope's resource effect: destructive questions: - Can I delete a role offered by a catalogued scope's resource? - Is removing a role from a catalogued scope's resource permanent? instructions: - text: Delete role {role} offered by catalogued scope {scope}'s resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Remove role {role} from the resource of catalogued scope {scope}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a catalogued scope's resource effect: write questions: - Can I rename a role offered by a catalogued scope's resource? - Which fields of a role on a catalogued scope's resource are editable? instructions: - text: Rename role {role} offered by catalogued scope {scope}'s resource for grant {grant} in {package} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Update role {role}'s description to {description} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id description: requestBody.description scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles on a catalogued scope's resource effect: read questions: - How many roles does a catalogued scope's resource offer? - Can I get just the role count for the resource of a catalogued scope? instructions: - text: Count roles offered by catalogued scope {scope}'s resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me the number of roles on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List uploads on a catalogued scope's resource effect: read questions: - Which custom data upload sessions exist for a catalogued scope's resource? - Can I review bring-your-own-data uploads for the resource of a catalogued scope? instructions: - text: List upload sessions for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show custom data uploads made to the resource of catalogued scope {scope}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload on a catalogued scope's resource effect: write questions: - How do I start an external access data upload for a catalogued scope's resource? - Can a new upload for a catalogued scope's resource carry my reference ID? instructions: - text: Start an upload session with reference ID {referenceId} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: referenceId: requestBody.referenceId scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Open a new custom data upload on the resource of catalogued scope {scope}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload on a catalogued scope's resource effect: read questions: - What is the status of one upload session on a catalogued scope's resource? - Has a particular catalogued scope resource upload finished processing? instructions: - text: Get upload session {session} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Check the stats of custom data upload {session} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload on a catalogued scope's resource effect: destructive questions: - Can I discard an upload session for a catalogued scope's resource? - What happens to files when a catalogued scope resource upload is deleted? instructions: - text: Delete upload session {session} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Discard the custom data upload {session} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload on a catalogued scope's resource effect: write questions: - How do I mark a catalogued scope resource upload as done? - Can I change the reference ID of an upload on a catalogued scope's resource? instructions: - text: Set isUploadDone to {isUploadDone} on upload session {session} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: isUploadDone: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Change upload {session}'s reference ID to {referenceId} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id referenceId: requestBody.referenceId scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalogued scope upload effect: read questions: - Which files were sent in an upload for a catalogued scope's resource? - Can I list the files inside a catalogued scope resource upload session? instructions: - text: List files in upload {session} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every uploaded file of session {session} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file record in a catalogued scope upload effect: read questions: - Can I read one file record from a catalogued scope resource upload? - What metadata does a file in a catalogued scope upload session carry? instructions: - text: Get file {file} of upload {session} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show the record for file {file} in session {session}, catalogued scope {scope}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a catalogued scope upload effect: read questions: - Can I download the bytes of a file uploaded to a catalogued scope's resource? - How do I retrieve the raw content of a catalogued scope upload file? instructions: - text: Download the content of file {file} in upload {session}, catalogued scope {scope}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Fetch raw bytes for file {file}, session {session}, on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Overwrite a file in a catalogued scope upload effect: write questions: - Can I overwrite a file already uploaded to a catalogued scope's resource? - How do I put new content into a catalogued scope upload file? instructions: - text: Overwrite file {file} with new content in upload {session}, catalogued scope {scope}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Replace what is stored for file {file}, session {session}, on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase a file's content in a catalogued scope upload effect: destructive questions: - Can I erase the stored content of a catalogued scope upload file? - Is wiping a file's bytes in a catalogued scope resource upload reversible? instructions: - text: Erase the stored bytes of file {file} in upload {session}, catalogued scope {scope}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Wipe file {file}'s content from session {session} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a catalogued scope upload effect: read questions: - How many files are in a catalogued scope resource upload session? - Can I get only the file total for an upload on a catalogued scope's resource? instructions: - text: Count the files in upload {session} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many files session {session} holds, catalogued scope {scope}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a catalogued scope's resource effect: write questions: - How do I upload an access data file for a catalogued scope's resource? - Can I add another file to an open catalogued scope upload session? instructions: - text: Upload a file into session {session} for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Push an access data file to upload {session} on catalogued scope {scope}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count uploads on a catalogued scope's resource effect: read questions: - How many upload sessions exist for a catalogued scope's resource? - Can I get only the session total for a catalogued scope's resource? instructions: - text: Count the upload sessions for catalogued scope {scope}'s resource, grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many custom data uploads catalogued scope {scope}'s resource has, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes within a grant role's owner effect: read questions: - How many scopes exist within the role-owning resource of a grant? - Can I get just the scope count inside a grant role's owner? instructions: - text: Count scopes within the role-owning resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me the number of scopes inside grant {grant}'s role owner, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List uploads on a grant role's owner effect: read questions: - Which custom data upload sessions exist for the role-owning resource of a grant? - Can I review bring-your-own-data uploads sent to a grant role's owner? instructions: - text: List upload sessions for the role-owning resource of grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show custom data uploads made to grant {grant}'s role owner, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload on a grant role's owner effect: write questions: - How do I start an external access data upload for the role-owning resource? - Can a new upload for a grant role's owner carry my reference ID? instructions: - text: Start an upload session with reference ID {referenceId} for the role-owning resource of grant {grant} in {package}. slots: referenceId: requestBody.referenceId grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Open a new custom data upload on grant {grant}'s role owner, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload on a grant role's owner effect: read questions: - What is the status of one upload session on the role-owning resource? - Has a particular upload to a grant role's owner finished processing? instructions: - text: Get upload session {session} for the role-owning resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Check the stats of custom data upload {session} on grant {grant}'s role owner, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload on a grant role's owner effect: destructive questions: - Can I discard an upload session for the role-owning resource? - What happens to files when an upload to a grant role's owner is deleted? instructions: - text: Delete upload session {session} for the role-owning resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Discard the custom data upload {session} on grant {grant}'s role owner, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload on a grant role's owner effect: write questions: - How do I mark an upload to the role-owning resource as done? - Can I change the reference ID of an upload on a grant role's owner? instructions: - text: Set isUploadDone to {isUploadDone} on upload session {session} for the role-owning resource of grant {grant} in {package}. slots: isUploadDone: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Change upload {session}'s reference ID to {referenceId} on grant {grant}'s role owner, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id referenceId: requestBody.referenceId grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload to a grant role's owner effect: read questions: - Which files were sent in an upload for the role-owning resource? - Can I list the files inside an upload session on a grant role's owner? instructions: - text: List files in upload {session} for the role-owning resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every uploaded file of session {session} on grant {grant}'s role owner, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file record uploaded to a grant role's owner effect: read questions: - Can I read one file record from an upload to the role-owning resource? - What metadata does a file uploaded to a grant role's owner carry? instructions: - text: Get file {file} of upload {session} for the role-owning resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show the record for file {file} in session {session}, grant {grant}'s role owner, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file uploaded to a grant role's owner effect: read questions: - Can I download the bytes of a file uploaded to the role-owning resource? - How do I retrieve the raw content of a file sent to a grant role's owner? instructions: - text: Download the content of file {file} in upload {session}, role-owning resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Fetch raw bytes for file {file}, session {session}, on grant {grant}'s role owner, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Overwrite a file uploaded to a grant role's owner effect: write questions: - Can I overwrite a file already uploaded to the role-owning resource? - How do I put new content into a file sent to a grant role's owner? instructions: - text: Overwrite file {file} with new content in upload {session}, role-owning resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Replace what is stored for file {file}, session {session}, on grant {grant}'s role owner, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase a file uploaded to a grant role's owner effect: destructive questions: - Can I erase the stored content of a file uploaded to the role-owning resource? - Is wiping a file's bytes on a grant role's owner reversible? instructions: - text: Erase the stored bytes of file {file} in upload {session}, role-owning resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Wipe file {file}'s content from session {session} on grant {grant}'s role owner, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload to a grant role's owner effect: read questions: - How many files are in an upload session on the role-owning resource? - Can I get only the file total for an upload to a grant role's owner? instructions: - text: Count the files in upload {session} for the role-owning resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many files session {session} holds, grant {grant}'s role owner, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a grant role's owner effect: write questions: - How do I upload an access data file for the role-owning resource? - Can I add another file to an open upload on a grant role's owner? instructions: - text: Upload a file into session {session} for the role-owning resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Push an access data file to upload {session} on grant {grant}'s role owner, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count uploads on a grant role's owner effect: read questions: - How many upload sessions exist for the role-owning resource of a grant? - Can I get only the session total for a grant role's owner? instructions: - text: Count the upload sessions for the role-owning resource of grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many custom data uploads grant {grant}'s role owner has, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope'].get update: x-apievangelist-phrasing: intent: Get the scope a resource grant covers effect: read questions: - Which scope of the resource does this package grant cover? - Can I check whether a grant applies at the root scope? instructions: - text: Get the scope covered by grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show which scope resource grant {grant} of package {package} applies to. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope'].delete update: x-apievangelist-phrasing: intent: Unlink the scope from a resource grant effect: destructive questions: - Is it possible to unlink the scope from a package's resource grant? - What happens when I clear the scope link on a grant? instructions: - text: Unlink the scope from grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Clear the covered scope on resource grant {grant} of package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope'].patch update: x-apievangelist-phrasing: intent: Update the scope a resource grant covers effect: write questions: - Can I rename the scope a resource grant covers? - Is it possible to flag a grant's covered scope as the root scope? instructions: - text: Rename the scope covered by grant {grant} in {package} to {name}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Set isRootScope to {isRootScope} on the scope of resource grant {grant}, package {package}. slots: isRootScope: requestBody.isRootScope grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource'].get update: x-apievangelist-phrasing: intent: Get the resource hosting a grant's scope effect: read questions: - Which app, group or site hosts the scope in this package grant? - Can I read the origin system of the scope-hosting resource? instructions: - text: Get the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show which application hosts the scope of grant {grant}, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource hosting a grant's scope effect: destructive questions: - Can I unlink the scope-hosting resource from a grant's scope? - What is lost if a grant scope's hosting resource link is deleted? instructions: - text: Unlink the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Delete the hosting resource link beneath grant {grant}'s scope, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource hosting a grant's scope effect: write questions: - Can I edit the display name of the scope-hosting resource? - Which attributes of a grant scope's hosting resource are patchable? instructions: - text: Rename the scope-hosting resource for grant {grant} in {package} to {name}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Change the scope-hosting resource description on grant {grant}, package {package}, to {description}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a grant scope's host effect: read questions: - Which environment is the scope-hosting resource in? - Can I read hosting environment details for a grant scope's host? instructions: - text: Get the environment of the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show where grant {grant}'s scope-hosting resource lives, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource hosting a grant's scope effect: write questions: - Can I trigger a re-sync of the scope-hosting resource behind a grant? - How do I pull newly added scopes from the resource hosting a grant's scope? instructions: - text: Refresh the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Re-sync the host of grant {grant}'s scope in package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles offered by a grant scope's host effect: read questions: - What roles are offered by the scope-hosting resource of a grant? - Can I list all roles on the resource hosting a grant's scope? instructions: - text: List roles offered by the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every role the host of grant {grant}'s scope offers, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a grant scope's host effect: write questions: - Can I add a new role offered by the scope-hosting resource? - Does a new role on a grant scope's host need an origin ID? instructions: - text: Add role {name} offered by the scope-hosting resource for grant {grant} in {package}. slots: name: requestBody.displayName grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Create a role with origin ID {originId} on grant {grant}'s scope host, package {package}. slots: originId: requestBody.originId grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role offered by a grant scope's host effect: read questions: - Can I read one role offered by the scope-hosting resource of a grant? - Where does a specific role on a grant scope's host originate? instructions: - text: Get role {role} offered by the scope-hosting resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show role {role} from the host of grant {grant}'s scope, package {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role offered by a grant scope's host effect: destructive questions: - Can I delete one role offered by the scope-hosting resource? - What breaks if a role on a grant scope's host is removed? instructions: - text: Delete role {role} offered by the scope-hosting resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Remove role {role} permanently from the host of grant {grant}'s scope, package {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role offered by a grant scope's host effect: write questions: - Can I rename a role offered by the scope-hosting resource? - Which fields of a role on a grant scope's host can change? instructions: - text: Rename role {role} offered by the scope-hosting resource for grant {grant} in {package} to {name}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Update role {role}'s description to {description} on the host of grant {grant}'s scope, package {package}. slots: role: path.accessPackageResourceRole-id description: requestBody.description grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource of a defined role effect: read questions: - Which resource is a defined role on a grant scope's host attached to? - Can I navigate from a defined role back to its resource on the scope-hosting branch? instructions: - text: Get the resource of defined role {role} for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show which resource defined role {role} is attached to, scope-hosting branch of grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a defined role effect: destructive questions: - Can I unlink the resource from a defined role on the scope-hosting branch? - What gets removed when a defined role's resource link is deleted? instructions: - text: Unlink the resource of defined role {role} for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Delete defined role {role}'s resource link, scope-hosting branch of grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource of a defined role effect: write questions: - Can I rename the resource behind a defined role on the scope-hosting branch? - Which fields of a defined role's resource can be patched? instructions: - text: Rename the resource of defined role {role} for grant {grant} in {package} to {name}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Set the description of defined role {role}'s resource to {description}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id description: requestBody.description grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a defined role's resource effect: read questions: - Where is a defined role's resource hosted, on the scope-hosting branch? - Can I get environment info for the resource of a defined role? instructions: - text: Get the environment of defined role {role}'s resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show hosting environment details for the resource of defined role {role}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a defined role's resource effect: write questions: - Can I re-sync the resource of a defined role on the scope-hosting branch? - How do I refresh a defined role's resource so new scopes appear? instructions: - text: Refresh defined role {role}'s resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Re-sync the resource behind defined role {role}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes on a defined role's resource effect: read questions: - Which scopes exist within a defined role's resource? - Can I list scopes for the resource of a defined role on the scope-hosting branch? instructions: - text: List scopes within defined role {role}'s resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show all scopes on the resource of defined role {role}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a defined role's resource effect: write questions: - Can I add a scope within a defined role's resource? - How do I make a new scope inside a defined role's resource the root scope? instructions: - text: Add scope {name} within defined role {role}'s resource for grant {grant} in {package}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Create a scope with isRootScope {isRootScope} on defined role {role}'s resource, grant {grant}, {package}. slots: isRootScope: requestBody.isRootScope role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope on a defined role's resource effect: read questions: - Can I read one scope within a defined role's resource? - Is a given scope inside a defined role's resource the root scope? instructions: - text: Get scope {scope} within defined role {role}'s resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show scope {scope} on the resource of defined role {role}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope on a defined role's resource effect: destructive questions: - Can I delete a scope within a defined role's resource? - Is removing a scope from a defined role's resource permanent? instructions: - text: Delete scope {scope} within defined role {role}'s resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Remove scope {scope} from the resource of defined role {role}, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a defined role's resource effect: write questions: - Can I rename a scope within a defined role's resource? - Which fields of a scope on a defined role's resource are editable? instructions: - text: Rename scope {scope} within defined role {role}'s resource for grant {grant} in {package} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id name: requestBody.displayName - text: Update scope {scope}'s description to {description} on defined role {role}'s resource, grant {grant}, {package}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes on a defined role's resource effect: read questions: - How many scopes does a defined role's resource have? - Is there a quick scope total for a defined role's resource? instructions: - text: Count scopes within defined role {role}'s resource for grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me the number of scopes on defined role {role}'s resource, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List uploads on a defined role's resource effect: read questions: - Which custom data upload sessions exist for a defined role's resource? - Can I review bring-your-own-data uploads for the resource of a defined role? instructions: - text: List upload sessions for defined role {role}'s resource, grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show custom data uploads made to the resource of defined role {role}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload on a defined role's resource effect: write questions: - How do I start an external access data upload for a defined role's resource? - Can a new upload for a defined role's resource carry my reference ID? instructions: - text: Start an upload session with reference ID {referenceId} for defined role {role}'s resource, grant {grant} in {package}. slots: referenceId: requestBody.referenceId role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Open a new custom data upload on the resource of defined role {role}, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload on a defined role's resource effect: read questions: - What is the status of one upload session on a defined role's resource? - Has a particular defined role resource upload finished processing? instructions: - text: Get upload session {session} for defined role {role}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Check the stats of custom data upload {session} on defined role {role}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload on a defined role's resource effect: destructive questions: - Can I discard an upload session for a defined role's resource? - What happens to files when a defined role resource upload is deleted? instructions: - text: Delete upload session {session} for defined role {role}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Discard the custom data upload {session} on defined role {role}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload on a defined role's resource effect: write questions: - How do I mark a defined role resource upload as done? - Can I change the reference ID of an upload on a defined role's resource? instructions: - text: Set isUploadDone to {isUploadDone} on upload session {session} for defined role {role}'s resource, grant {grant} in {package}. slots: isUploadDone: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Change upload {session}'s reference ID to {referenceId} on defined role {role}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id referenceId: requestBody.referenceId role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a defined role upload effect: read questions: - Which files were sent in an upload for a defined role's resource? - Can I list the files inside a defined role resource upload session? instructions: - text: List files in upload {session} for defined role {role}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every uploaded file of session {session} on defined role {role}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file record in a defined role upload effect: read questions: - Can I read one file record from a defined role resource upload? - What metadata does a file in a defined role upload session carry? instructions: - text: Get file {file} of upload {session} for defined role {role}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show the record for file {file} in session {session}, defined role {role}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a defined role upload effect: read questions: - Can I download the bytes of a file uploaded to a defined role's resource? - How do I retrieve the raw content of a defined role upload file? instructions: - text: Download the content of file {file} in upload {session}, defined role {role}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Fetch raw bytes for file {file}, session {session}, on defined role {role}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Overwrite a file in a defined role upload effect: write questions: - Can I overwrite a file already uploaded to a defined role's resource? - How do I put new content into a defined role upload file? instructions: - text: Overwrite file {file} with new content in upload {session}, defined role {role}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Replace what is stored for file {file}, session {session}, on defined role {role}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase a file's content in a defined role upload effect: destructive questions: - Can I erase the stored content of a defined role upload file? - Is wiping a file's bytes in a defined role resource upload reversible? instructions: - text: Erase the stored bytes of file {file} in upload {session}, defined role {role}'s resource, grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Wipe file {file}'s content from session {session} on defined role {role}'s resource, grant {grant}, {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a defined role upload effect: read questions: - How many files are in a defined role resource upload session? - Can I get only the file total for an upload on a defined role's resource? instructions: - text: Count the files in upload {session} for defined role {role}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many files session {session} holds, defined role {role}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a defined role's resource effect: write questions: - How do I upload an access data file for a defined role's resource? - Can I add another file to an open defined role upload session? instructions: - text: Upload a file into session {session} for defined role {role}'s resource, grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Push an access data file to upload {session} on defined role {role}'s resource, grant {grant}, {package}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count uploads on a defined role's resource effect: read questions: - How many upload sessions exist for a defined role's resource? - Can I get only the session total for a defined role's resource? instructions: - text: Count the upload sessions for defined role {role}'s resource, grant {grant} in {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many custom data uploads defined role {role}'s resource has, grant {grant}, {package}. slots: role: path.accessPackageResourceRole-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles offered by a grant scope's host effect: read questions: - How many roles does the scope-hosting resource of a grant offer? - Is there a quick count of roles on a grant scope's host? instructions: - text: Count roles offered by the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me the number of roles grant {grant}'s scope host has, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes within a grant scope's host effect: read questions: - Which scopes exist within the scope-hosting resource of a grant? - Can I see sibling scopes on the resource hosting a grant's scope? instructions: - text: List scopes within the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every scope inside grant {grant}'s scope host, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope within a grant scope's host effect: write questions: - Can I add a scope within the scope-hosting resource? - How do I flag a new scope on a grant scope's host as root? instructions: - text: Add scope {name} within the scope-hosting resource for grant {grant} in {package}. slots: name: requestBody.displayName grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Create a scope on grant {grant}'s scope host with isRootScope {isRootScope}, package {package}. slots: grant: path.accessPackageResourceRoleScope-id isRootScope: requestBody.isRootScope package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope within a grant scope's host effect: read questions: - Can I read one scope within the scope-hosting resource? - Is a given scope on a grant scope's host the root scope? instructions: - text: Get scope {scope}, one of the scopes within the scope-hosting resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show scope {scope} on grant {grant}'s scope host, package {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope within a grant scope's host effect: destructive questions: - Can I delete a scope within the scope-hosting resource? - What happens when a scope on a grant scope's host is removed? instructions: - text: Delete scope {scope} within the scope-hosting resource for grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Remove scope {scope} from grant {grant}'s scope host, package {package}. slots: scope: path.accessPackageResourceScope-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope within a grant scope's host effect: write questions: - Can I rename a scope within the scope-hosting resource? - Which scope fields on a grant scope's host are patchable? instructions: - text: Give scope {scope} inside the scope-hosting resource the new name {name}, grant {grant} in {package}. slots: scope: path.accessPackageResourceScope-id name: requestBody.displayName grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Update scope {scope}'s description to {description} on grant {grant}'s scope host, package {package}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes within a grant scope's host effect: read questions: - How many scopes exist within the scope-hosting resource of a grant? - Can I get just the scope count on a grant scope's host? instructions: - text: Count scopes within the scope-hosting resource for grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me the number of scopes on grant {grant}'s scope host, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List uploads on a grant scope's host effect: read questions: - Which custom data upload sessions exist for the scope-hosting resource of a grant? - Can I review bring-your-own-data uploads sent to a grant scope's host? instructions: - text: List upload sessions for the scope-hosting resource of grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show custom data uploads made to grant {grant}'s scope host, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload on a grant scope's host effect: write questions: - How do I start an external access data upload for the scope-hosting resource? - Can a new upload for a grant scope's host carry my reference ID? instructions: - text: Start an upload session with reference ID {referenceId} for the scope-hosting resource of grant {grant} in {package}. slots: referenceId: requestBody.referenceId grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Open a new custom data upload on grant {grant}'s scope host, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload on a grant scope's host effect: read questions: - What is the status of one upload session on the scope-hosting resource? - Has a particular upload to a grant scope's host finished processing? instructions: - text: Get upload session {session} for the scope-hosting resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Check the stats of custom data upload {session} on grant {grant}'s scope host, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload on a grant scope's host effect: destructive questions: - Can I discard an upload session for the scope-hosting resource? - What happens to files when an upload to a grant scope's host is deleted? instructions: - text: Delete upload session {session} for the scope-hosting resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Discard the custom data upload {session} on grant {grant}'s scope host, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload on a grant scope's host effect: write questions: - How do I mark an upload to the scope-hosting resource as done? - Can I change the reference ID of an upload on a grant scope's host? instructions: - text: Set isUploadDone to {isUploadDone} on upload session {session} for the scope-hosting resource of grant {grant} in {package}. slots: isUploadDone: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Change upload {session}'s reference ID to {referenceId} on grant {grant}'s scope host, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id referenceId: requestBody.referenceId grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload to a grant scope's host effect: read questions: - Which files were sent in an upload for the scope-hosting resource? - Can I list the files inside an upload session on a grant scope's host? instructions: - text: List files in upload {session} for the scope-hosting resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show every uploaded file of session {session} on grant {grant}'s scope host, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file record uploaded to a grant scope's host effect: read questions: - Can I read one file record from an upload to the scope-hosting resource? - What metadata does a file uploaded to a grant scope's host carry? instructions: - text: Get file {file} of upload {session} for the scope-hosting resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Show the record for file {file} in session {session}, grant {grant}'s scope host, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file uploaded to a grant scope's host effect: read questions: - Can I download the bytes of a file uploaded to the scope-hosting resource? - How do I retrieve the raw content of a file sent to a grant scope's host? instructions: - text: Download the content of file {file} in upload {session}, scope-hosting resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Fetch raw bytes for file {file}, session {session}, on grant {grant}'s scope host, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Overwrite a file uploaded to a grant scope's host effect: write questions: - Can I overwrite a file already uploaded to the scope-hosting resource? - How do I put new content into a file sent to a grant scope's host? instructions: - text: Overwrite file {file} with new content in upload {session}, scope-hosting resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Replace what is stored for file {file}, session {session}, on grant {grant}'s scope host, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase a file uploaded to a grant scope's host effect: destructive questions: - Can I erase the stored content of a file uploaded to the scope-hosting resource? - Is wiping a file's bytes on a grant scope's host reversible? instructions: - text: Erase the stored bytes of file {file} in upload {session}, scope-hosting resource of grant {grant} in {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Wipe file {file}'s content from session {session} on grant {grant}'s scope host, package {package}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload to a grant scope's host effect: read questions: - How many files are in an upload session on the scope-hosting resource? - Can I get only the file total for an upload to a grant scope's host? instructions: - text: Count the files in upload {session} for the scope-hosting resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many files session {session} holds, grant {grant}'s scope host, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a grant scope's host effect: write questions: - How do I upload an access data file for the scope-hosting resource? - Can I add another file to an open upload on a grant scope's host? instructions: - text: Upload a file into session {session} for the scope-hosting resource of grant {grant} in {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Push an access data file to upload {session} on grant {grant}'s scope host, package {package}. slots: session: path.customDataProvidedResourceUploadSession-id grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count uploads on a grant scope's host effect: read questions: - How many upload sessions exist for the scope-hosting resource of a grant? - Can I get only the session total for a grant scope's host? instructions: - text: Count the upload sessions for the scope-hosting resource of grant {grant} in {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id - text: Tell me how many custom data uploads grant {grant}'s scope host has, package {package}. slots: grant: path.accessPackageResourceRoleScope-id package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/{accessPackage-id}/resourceRoleScopes/$count'].get update: x-apievangelist-phrasing: intent: Count the resource grants in a package effect: read questions: - How many resource roles does this access package grant in total? - Can I get only the number of role-and-scope pairings in a package? instructions: - text: Count the resource grants in access package {package}. slots: package: path.accessPackage-id - text: Tell me how many resource role scopes package {package} contains. slots: package: path.accessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/$count'].get update: x-apievangelist-phrasing: intent: Count access packages effect: read questions: - How many access packages exist in the tenant? - Is there a quick way to get the total number of access packages? instructions: - text: Count all access packages. - text: Give me the total number of access packages in entitlement management. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackages/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get update: x-apievangelist-phrasing: intent: List access packages I can request effect: read questions: - Which access packages am I, the signed-in user, allowed to request? - Can I filter the access package list to the ones that apply to me? instructions: - text: List the access packages where I am the {on}. slots: 'on': path.on - text: Show access packages filtered to the current user as {on}. slots: 'on': path.on method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions'].get update: x-apievangelist-phrasing: intent: List suggested access packages effect: read questions: - What access packages are being suggested to end users? - Can I see package suggestions based on related people and assignment history? instructions: - text: List all access package suggestions. - text: Show the suggested access packages and their reasons. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions'].post update: x-apievangelist-phrasing: intent: Create an access package suggestion effect: write questions: - Can I add a suggestion record that points users to an access package? - What goes into a new package suggestion, such as reasons? instructions: - text: Create a suggestion for access package {packageBody}. slots: packageBody: requestBody.accessPackage - text: Add a package suggestion with reasons {reasons}. slots: reasons: requestBody.reasons method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions/{accessPackageSuggestion-id}'].get update: x-apievangelist-phrasing: intent: Get an access package suggestion effect: read questions: - Why was a specific access package suggested? - Can I read one suggestion record and its reasons? instructions: - text: Get access package suggestion {suggestion}. slots: suggestion: path.accessPackageSuggestion-id - text: Show the reasons behind suggestion {suggestion}. slots: suggestion: path.accessPackageSuggestion-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions/{accessPackageSuggestion-id}'].delete update: x-apievangelist-phrasing: intent: Delete an access package suggestion effect: destructive questions: - Can I remove a suggestion so users stop seeing a package recommended? - Is deleting an access package suggestion permanent? instructions: - text: Delete access package suggestion {suggestion}. slots: suggestion: path.accessPackageSuggestion-id - text: Remove the package recommendation {suggestion}. slots: suggestion: path.accessPackageSuggestion-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions/{accessPackageSuggestion-id}'].patch update: x-apievangelist-phrasing: intent: Update an access package suggestion effect: write questions: - Can I change the reasons recorded on a package suggestion? - Is it possible to repoint an existing suggestion to a different access package? instructions: - text: Update the reasons on suggestion {suggestion} to {reasons}. slots: suggestion: path.accessPackageSuggestion-id reasons: requestBody.reasons - text: Point suggestion {suggestion} at access package {packageBody}. slots: suggestion: path.accessPackageSuggestion-id packageBody: requestBody.accessPackage method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions/{accessPackageSuggestion-id}/accessPackage'].get update: x-apievangelist-phrasing: intent: Get the package behind a suggestion effect: read questions: - Which access package does a given suggestion recommend? - Can I read the full package details straight from a suggestion? instructions: - text: Get the access package recommended by suggestion {suggestion}. slots: suggestion: path.accessPackageSuggestion-id - text: Show which package suggestion {suggestion} points to. slots: suggestion: path.accessPackageSuggestion-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions/$count'].get update: x-apievangelist-phrasing: intent: Count access package suggestions effect: read questions: - How many access package suggestions are there? - Can I get only the total number of package suggestions? instructions: - text: Count all access package suggestions. - text: Tell me how many package recommendations exist. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/accessPackageSuggestions/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get update: x-apievangelist-phrasing: intent: List packages suggested for me effect: read questions: - Which access packages are recommended for me personally? - Can I get suggestions tailored to my role and assignment history as the signed-in user? instructions: - text: List the package suggestions for me as {on}. slots: 'on': path.on - text: Show access package suggestions filtered to the current user as {on}. slots: 'on': path.on method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies'].get update: x-apievangelist-phrasing: intent: List all assignment policies effect: read questions: - What assignment policies exist across all access packages in the tenant? - Can I filter the tenant-wide policy list by display name? instructions: - text: List every access package assignment policy in the tenant. - text: Show all assignment policies across entitlement management. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies'].post update: x-apievangelist-phrasing: intent: Create an assignment policy effect: write questions: - How do I create a new access package assignment policy at the top level? - Which settings, like allowed target scope and expiration, can a new policy define? instructions: - text: Create an assignment policy named {name} for access package {packageBody}. slots: name: requestBody.displayName packageBody: requestBody.accessPackage - text: Create a policy {name} with target scope {targetScope} and expiration {expiration}. slots: name: requestBody.displayName targetScope: requestBody.allowedTargetScope expiration: requestBody.expiration method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}'].get update: x-apievangelist-phrasing: intent: Get an assignment policy effect: read questions: - Where can I read the full properties of an access package assignment policy by ID? - Can I expand a policy to see its questions and custom extension stages? instructions: - text: Get assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Show policy {policy} with its questions expanded. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}'].put update: x-apievangelist-phrasing: intent: Replace an assignment policy effect: write questions: - How do I update the display name or description of an assignment policy? - Does changing an assignment policy require sending the whole object? instructions: - text: Update assignment policy {policy} with display name {name}. slots: policy: path.accessPackageAssignmentPolicy-id name: requestBody.displayName - text: Replace the description of policy {policy} with {description}. slots: policy: path.accessPackageAssignmentPolicy-id description: requestBody.description - text: Change the expiration settings of assignment policy {policy} to {expiration}. slots: policy: path.accessPackageAssignmentPolicy-id expiration: requestBody.expiration method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}'].delete update: x-apievangelist-phrasing: intent: Delete an assignment policy effect: destructive questions: - Can I delete an access package assignment policy directly by its ID? - What happens to pending requests when an assignment policy is deleted? instructions: - text: Delete assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Remove access package policy {policy} from entitlement management. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/accessPackage'].get update: x-apievangelist-phrasing: intent: Get the package a policy belongs to effect: read questions: - Which access package does this assignment policy control? - Can I go from a policy ID straight to its access package? instructions: - text: Get the access package for assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Show which package policy {policy} governs. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/catalog'].get update: x-apievangelist-phrasing: intent: Get the catalog of a policy's package effect: read questions: - Which catalog holds the access package that this policy governs? - Can I look up the catalog directly from an assignment policy ID? instructions: - text: Get the catalog for assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Show which catalog policy {policy} falls under. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings'].get update: x-apievangelist-phrasing: intent: List custom extension stages on a policy effect: read questions: - At which stages does an assignment policy call custom workflow extensions? - Can I list a policy's Logic App triggers without going through its access package? instructions: - text: List the custom extension stage settings of assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Show when assignment policy {policy} runs custom extensions. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings'].post update: x-apievangelist-phrasing: intent: Add a custom extension stage to a policy effect: write questions: - How do I make an assignment policy run a custom extension when a request is granted? - Can I attach a workflow extension to a policy by the policy ID alone? instructions: - text: Add custom extension {extension} at stage {trigger} to assignment policy {policy}. slots: extension: requestBody.customExtension trigger: requestBody.stage policy: path.accessPackageAssignmentPolicy-id - text: Create an extension trigger for stage {trigger} on assignment policy {policy}. slots: trigger: requestBody.stage policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}'].get update: x-apievangelist-phrasing: intent: Get a custom extension stage on a policy effect: read questions: - What stage does one custom extension setting on an assignment policy fire at? - Can I read a single extension trigger of a policy by its ID? instructions: - text: Get custom extension stage setting {setting} of assignment policy {policy}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id - text: Show extension trigger {setting} on assignment policy {policy}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}'].delete update: x-apievangelist-phrasing: intent: Remove a custom extension stage from a policy effect: destructive questions: - Can I stop an assignment policy from calling a workflow extension at a stage? - Is removing an extension trigger from a policy permanent? instructions: - text: Delete custom extension stage setting {setting} from assignment policy {policy}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id - text: Remove extension trigger {setting} on assignment policy {policy}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}'].patch update: x-apievangelist-phrasing: intent: Update a custom extension stage on a policy effect: write questions: - Can I move a policy's custom extension to run at a different stage? - Is it possible to swap which extension an assignment policy trigger calls? instructions: - text: Change extension trigger {setting} on assignment policy {policy} to stage {trigger}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id trigger: requestBody.stage - text: Point stage setting {setting} of assignment policy {policy} to custom extension {extension}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id extension: requestBody.customExtension method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/{customExtensionStageSetting-id}/customExtension'].get update: x-apievangelist-phrasing: intent: Get the extension a policy stage runs effect: read questions: - Which custom workflow extension runs at this stage of an assignment policy? - Can I read the Logic App endpoint behind a policy's extension trigger? instructions: - text: Get the custom extension run by stage setting {setting} of assignment policy {policy}. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id - text: Show which workflow extension trigger {setting} on assignment policy {policy} calls. slots: setting: path.customExtensionStageSetting-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/customExtensionStageSettings/$count'].get update: x-apievangelist-phrasing: intent: Count custom extension stages on a policy effect: read questions: - How many custom extension triggers does an assignment policy have? - Can I get only the number of extension stage settings for a policy ID? instructions: - text: Count the custom extension stage settings on assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Tell me how many extension triggers assignment policy {policy} has. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions'].get update: x-apievangelist-phrasing: intent: List requestor questions on a policy effect: read questions: - What questions does an assignment policy ask requestors? - Can I list a policy's questions in order without going through its package? instructions: - text: List the requestor questions on assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Show every question assignment policy {policy} asks. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions'].post update: x-apievangelist-phrasing: intent: Add a requestor question to a policy effect: write questions: - How do I add a required question to an assignment policy by policy ID? - Can I set the display order of a new question on a policy? instructions: - text: Add question {text} to assignment policy {policy}. slots: text: requestBody.text policy: path.accessPackageAssignmentPolicy-id - text: Create question {text} in position {sequence} on assignment policy {policy}. slots: text: requestBody.text sequence: requestBody.sequence policy: path.accessPackageAssignmentPolicy-id - text: Add a question to assignment policy {policy} with isRequired {isRequired}. slots: policy: path.accessPackageAssignmentPolicy-id isRequired: requestBody.isRequired method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/{accessPackageQuestion-id}'].get update: x-apievangelist-phrasing: intent: Get a requestor question on a policy effect: read questions: - Can I read one question of an assignment policy by its ID? - Is a particular policy question editable after the requestor answers? instructions: - text: Get question {question} on assignment policy {policy}. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id - text: Show whether policy question {question} on {policy} lets requestors edit answers. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/{accessPackageQuestion-id}'].delete update: x-apievangelist-phrasing: intent: Remove a requestor question from a policy effect: destructive questions: - Can I delete a question from an assignment policy directly? - Will requestors stop seeing a question once it is removed from the policy? instructions: - text: Delete question {question} from assignment policy {policy}. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id - text: Drop requestor question {question} on assignment policy {policy}. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/{accessPackageQuestion-id}'].patch update: x-apievangelist-phrasing: intent: Edit a requestor question on a policy effect: write questions: - Can I reword a question on an assignment policy? - Is it possible to make an existing policy question required? instructions: - text: Reword question {question} on assignment policy {policy} to {text}. slots: question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id text: requestBody.text - text: Set isRequired to {isRequired} on question {question} of assignment policy {policy}. slots: isRequired: requestBody.isRequired question: path.accessPackageQuestion-id policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/{accessPackageAssignmentPolicy-id}/questions/$count'].get update: x-apievangelist-phrasing: intent: Count requestor questions on a policy effect: read questions: - How many questions does an assignment policy ask? - Can I get just the question count for a policy ID? instructions: - text: Count the questions on assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id - text: Give me the requestor question total for assignment policy {policy}. slots: policy: path.accessPackageAssignmentPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentPolicies/$count'].get update: x-apievangelist-phrasing: intent: Count access package assignment policies effect: read questions: - How many access package assignment policies are defined in my Entra tenant? - Can I count only the assignment policies that match a filter? instructions: - text: Count the access package assignment policies in my tenant. - text: Count assignment policies matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests'].get update: x-apievangelist-phrasing: intent: List access package requests effect: read questions: - Where can I see every access package request, current and expired, across all catalogs? - Can I filter access package requests by state or requestor? instructions: - text: List every access package assignment request. - text: List access package requests matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests'].post update: x-apievangelist-phrasing: intent: Request or assign an access package effect: write questions: - How do I request an access package for a user in Microsoft Entra? - Can an admin assign, update or remove someone's access package by filing a request? instructions: - text: Submit an access package request of type {requestType} with justification {justification}. slots: requestType: requestBody.requestType justification: requestBody.justification - text: File a new access request, giving {justification} as the business reason. slots: justification: requestBody.justification method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}'].get update: x-apievangelist-phrasing: intent: Get an access package request effect: read questions: - What is the current state of one specific access package request? - Where do I see the answers and schedule submitted on a single access request? instructions: - text: Show access package request {request}. slots: request: path.accessPackageAssignmentRequest-id - text: Get the status and justification of access request {request}. slots: request: path.accessPackageAssignmentRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}'].delete update: x-apievangelist-phrasing: intent: Delete a denied or completed access request effect: destructive questions: - Can I remove an access package request that was denied or already completed? - Why can't I delete an access request that still has assignments attached? instructions: - text: Delete access package request {request}. slots: request: path.accessPackageAssignmentRequest-id - text: Purge the denied access request {request}. slots: request: path.accessPackageAssignmentRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}'].patch update: x-apievangelist-phrasing: intent: Update an access package request effect: write questions: - Can I edit the justification on an access package request after submitting it? - Is it possible to patch the state recorded on an existing access request? instructions: - text: Update access request {request} with justification {justification}. slots: request: path.accessPackageAssignmentRequest-id justification: requestBody.justification - text: Set the state of access request {request} to {state}. slots: request: path.accessPackageAssignmentRequest-id state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}/accessPackage'].get update: x-apievangelist-phrasing: intent: Get the package an access request is for effect: read questions: - Which access package was a given access request asking for? - What package definition sits behind a user's pending request? instructions: - text: Show the access package that request {request} asks for. slots: request: path.accessPackageAssignmentRequest-id - text: Get package details behind access request {request}. slots: request: path.accessPackageAssignmentRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}/assignment'].get update: x-apievangelist-phrasing: intent: Get the assignment an access request affects effect: read questions: - What assignment did an access package request create or remove? - Can I see the resulting assignment for an approved access request? instructions: - text: Show the assignment produced by access request {request}. slots: request: path.accessPackageAssignmentRequest-id - text: Get the access package assignment linked to request {request}. slots: request: path.accessPackageAssignmentRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}/microsoft.graph.cancel'].post update: x-apievangelist-phrasing: intent: Cancel a pending access package request effect: destructive questions: - How do I cancel an access package request still awaiting approval? - Which request states can still be cancelled, like pendingApproval or accepted? instructions: - text: Cancel access package request {request}. slots: request: path.accessPackageAssignmentRequest-id - text: Withdraw the pending access request {request} before it is approved. slots: request: path.accessPackageAssignmentRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}/microsoft.graph.reprocess'].post update: x-apievangelist-phrasing: intent: Retry a failed access package request effect: write questions: - Can I retry a user's access request that ended in DeliveryFailed? - Is there a 14-day limit on reprocessing a partially delivered request? instructions: - text: Reprocess access request {request}. slots: request: path.accessPackageAssignmentRequest-id - text: Retry delivery of the failed access package request {request}. slots: request: path.accessPackageAssignmentRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}/microsoft.graph.resume'].post update: x-apievangelist-phrasing: intent: Resume a request waiting on a custom extension effect: write questions: - How do I resume an access request that's waiting for a custom extension callback? - Can my workflow tell entitlement management to continue a request stuck in WaitingForCallback? instructions: - text: Resume access request {request} now that the custom extension has finished. slots: request: path.accessPackageAssignmentRequest-id - text: Resume paused request {request} with callback source {source} and type {type}. slots: request: path.accessPackageAssignmentRequest-id source: requestBody.source type: requestBody.type method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/{accessPackageAssignmentRequest-id}/requestor'].get update: x-apievangelist-phrasing: intent: Get who submitted an access request effect: read questions: - Who submitted a particular access package request? - For a direct admin assignment, which subject was assigned in the request? instructions: - text: Show who requested access in request {request}. slots: request: path.accessPackageAssignmentRequest-id - text: Get the requestor of access package request {request}. slots: request: path.accessPackageAssignmentRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/$count'].get update: x-apievangelist-phrasing: intent: Count access package requests effect: read questions: - How many access package requests exist right now? - Can I count only the access requests matching a search phrase? instructions: - text: Count all access package assignment requests. - text: Count access requests matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignmentRequests/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get update: x-apievangelist-phrasing: intent: List my own access package requests effect: read questions: - Which access package requests did I personally submit? - Can I see only the access requests where I'm the target rather than the creator? instructions: - text: List access package requests filtered on me as {on}. slots: 'on': path.on - text: Show my own access requests where I am the {on}. slots: 'on': path.on method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments'].get update: x-apievangelist-phrasing: intent: List access package assignments effect: read questions: - Who currently holds access package assignments in my tenant? - Do catalog-scoped admins need to filter assignments by a specific access package? instructions: - text: List all access package assignments. - text: List access package assignments matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments'].post update: x-apievangelist-phrasing: intent: Create an access package assignment record effect: write questions: - Can I add an access package assignment record directly instead of through a request? - Is it possible to set an expiry date when adding an assignment record? instructions: - text: Create an access package assignment expiring at {expires}. slots: expires: requestBody.expiredDateTime - text: Add a new assignment record in state {state}. slots: state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/{accessPackageAssignment-id}'].get update: x-apievangelist-phrasing: intent: Get an access package assignment effect: read questions: - What are the details of one specific access package assignment? - When does a particular user's access package assignment expire? instructions: - text: Show access package assignment {assignment}. slots: assignment: path.accessPackageAssignment-id - text: Get the schedule and state of assignment {assignment}. slots: assignment: path.accessPackageAssignment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/{accessPackageAssignment-id}'].delete update: x-apievangelist-phrasing: intent: Delete an access package assignment effect: destructive questions: - Can I delete an access package assignment record outright? - What's the way to clear a stale assignment out of entitlement management? instructions: - text: Delete access package assignment {assignment}. slots: assignment: path.accessPackageAssignment-id - text: Erase stale assignment {assignment}. slots: assignment: path.accessPackageAssignment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/{accessPackageAssignment-id}'].patch update: x-apievangelist-phrasing: intent: Update an access package assignment effect: write questions: - Can I change the expiration date on an existing access package assignment? - Is there a way to patch the state of an assignment? instructions: - text: Update assignment {assignment} to expire at {expires}. slots: assignment: path.accessPackageAssignment-id expires: requestBody.expiredDateTime - text: Set assignment {assignment} state to {state}. slots: assignment: path.accessPackageAssignment-id state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/{accessPackageAssignment-id}/accessPackage'].get update: x-apievangelist-phrasing: intent: Get the package an assignment grants effect: read questions: - Which access package does a given assignment grant? - Where do I see the package behind a user's current assignment? instructions: - text: Show the access package granted by assignment {assignment}. slots: assignment: path.accessPackageAssignment-id - text: Get package details for assignment {assignment}. slots: assignment: path.accessPackageAssignment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/{accessPackageAssignment-id}/assignmentPolicy'].get update: x-apievangelist-phrasing: intent: Get the policy behind an assignment effect: read questions: - Which policy governs a given access package assignment? - What approval and expiry rules apply to one user's assignment? instructions: - text: Show the assignment policy behind assignment {assignment}. slots: assignment: path.accessPackageAssignment-id - text: Get the policy that assignment {assignment} was created under. slots: assignment: path.accessPackageAssignment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/{accessPackageAssignment-id}/microsoft.graph.reprocess'].post update: x-apievangelist-phrasing: intent: Re-evaluate and enforce an assignment effect: write questions: - Can I re-enforce a delivered access package assignment whose resource access drifted? - What role do I need to reprocess a user's assignment? instructions: - text: Reprocess assignment {assignment}. slots: assignment: path.accessPackageAssignment-id - text: Re-apply resource access for delivered assignment {assignment}. slots: assignment: path.accessPackageAssignment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/{accessPackageAssignment-id}/target'].get update: x-apievangelist-phrasing: intent: Get who an assignment is for effect: read questions: - Who is the subject of an access package assignment? - Which user or service principal holds a particular assignment? instructions: - text: Show the target subject of assignment {assignment}. slots: assignment: path.accessPackageAssignment-id - text: Get who assignment {assignment} was granted to. slots: assignment: path.accessPackageAssignment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/$count'].get update: x-apievangelist-phrasing: intent: Count access package assignments effect: read questions: - How many access package assignments are there in total? - Can I count only assignments that match a filter? instructions: - text: Count all access package assignments. - text: Count assignments matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/microsoft.graph.additionalAccess()'].get update: x-apievangelist-phrasing: intent: List assignments flagged as additional access effect: read questions: - Which access package assignments give users extra access through packages marked incompatible, across the whole tenant? - Can I page through every additional-access assignment without naming two specific packages? instructions: - text: List all access package assignments that count as additional access, without picking specific packages. - text: Show the first {top} additional-access assignments across entitlement management. slots: top: query.$top method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/microsoft.graph.additionalAccess(accessPackageId=\'{accessPackageId}\',incompatibleAccessPackageId=\'{incompatibleAccessPackageId}\')'].get update: x-apievangelist-phrasing: intent: Find users holding two specific access packages effect: read questions: - Can I check who holds a given access package and also a specific incompatible one? - Which targets are assigned both packages I plan to mark incompatible? instructions: - text: List users assigned {packageId} who also hold incompatible package {incompatibleId}. slots: packageId: path.accessPackageId incompatibleId: path.incompatibleAccessPackageId - text: Check overlap between access package {packageId} and {incompatibleId}. slots: packageId: path.accessPackageId incompatibleId: path.incompatibleAccessPackageId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/assignments/microsoft.graph.filterByCurrentUser(on=\'{on}\')'].get update: x-apievangelist-phrasing: intent: List my own access package assignments effect: read questions: - Which access package assignments do I personally have? - Can I see just the assignments targeted at me? instructions: - text: List my access package assignments filtered on {on}. slots: 'on': path.on - text: Show assignments where I am the {on}. slots: 'on': path.on method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages'].get update: x-apievangelist-phrasing: intent: List access packages users can request effect: read questions: - Which access packages can end users browse and request? - What does the self-service list of requestable packages contain? instructions: - text: List the access packages available for users to request. - text: Show available access packages matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages'].post update: x-apievangelist-phrasing: intent: Add an available access package entry effect: write questions: - Can I add an entry to the list of requestable access packages? - Is it possible to give a new available package a description when adding it? instructions: - text: Add an available access package named {name}. slots: name: requestBody.displayName - text: Create an available access package called {name} described as {description}. slots: name: requestBody.displayName description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages/{availableAccessPackage-id}'].get update: x-apievangelist-phrasing: intent: Get an available access package effect: read questions: - What does one requestable access package offer end users? - Where do I read the name and description of a single browsable package? instructions: - text: Show available access package {available}. slots: available: path.availableAccessPackage-id - text: Get the name and description of requestable package {available}. slots: available: path.availableAccessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages/{availableAccessPackage-id}'].delete update: x-apievangelist-phrasing: intent: Remove an available access package entry effect: destructive questions: - Can I take a package off the list end users browse to request? - What happens if I delete an available access package entry? instructions: - text: Delete available access package {available}. slots: available: path.availableAccessPackage-id - text: Take requestable package {available} off the browse list. slots: available: path.availableAccessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages/{availableAccessPackage-id}'].patch update: x-apievangelist-phrasing: intent: Update an available access package effect: write questions: - Can I rename a package on the requestable list? - Is there a way to fix the description users see on an available package? instructions: - text: Rename available access package {available} to {name}. slots: available: path.availableAccessPackage-id name: requestBody.displayName - text: Update the description of available package {available} to {description}. slots: available: path.availableAccessPackage-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages/{availableAccessPackage-id}/resourceRoleScopes'].get update: x-apievangelist-phrasing: intent: List roles an available package grants effect: read questions: - What resource roles and scopes does a requestable access package grant? - Before requesting a package, can a user see which roles it includes? instructions: - text: List resource role scopes of available package {available}. slots: available: path.availableAccessPackage-id - text: Show which roles and scopes available access package {available} includes. slots: available: path.availableAccessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages/{availableAccessPackage-id}/resourceRoleScopes/{accessPackageResourceRoleScope-id}'].get update: x-apievangelist-phrasing: intent: Get one role scope of an available package effect: read questions: - Can I inspect a single resource role scope on a requestable package? - What role and scope does one entry of an available package point to? instructions: - text: Show resource role scope {rrs} of available package {available}. slots: rrs: path.accessPackageResourceRoleScope-id available: path.availableAccessPackage-id - text: Get role scope entry {rrs} on requestable package {available}. slots: rrs: path.accessPackageResourceRoleScope-id available: path.availableAccessPackage-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages/{availableAccessPackage-id}/resourceRoleScopes/$count'].get update: x-apievangelist-phrasing: intent: Count role scopes of an available package effect: read questions: - How many resource role scopes does a requestable package bundle? - Can I count the role scopes in an available access package with a filter? instructions: - text: Count resource role scopes in available package {available}. slots: available: path.availableAccessPackage-id - text: Tally role scopes of requestable package {available} matching {filter}. slots: available: path.availableAccessPackage-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/availableAccessPackages/$count'].get update: x-apievangelist-phrasing: intent: Count available access packages effect: read questions: - How many access packages are available for users to request? - Can I count only the requestable packages matching a search? instructions: - text: Count the access packages available to request. - text: Count requestable packages matching {search}. slots: search: query.$search method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs'].get update: x-apievangelist-phrasing: intent: List access package catalogs effect: read questions: - Which access package catalogs exist in my tenant? - Can I filter catalogs by name or external visibility? instructions: - text: List all access package catalogs. - text: List catalogs matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs'].post update: x-apievangelist-phrasing: intent: Create an access package catalog effect: write questions: - How do I create a new catalog to hold access packages and resources? - Can I make a catalog visible to users from outside my organization when I create it? instructions: - text: Create an access package catalog named {name}. slots: name: requestBody.displayName - text: Create catalog {name} with external visibility set to {external}. slots: name: requestBody.displayName external: requestBody.isExternallyVisible method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}'].get update: x-apievangelist-phrasing: intent: Get an access package catalog effect: read questions: - What are the properties of one access package catalog? - Is a particular catalog published and externally visible? instructions: - text: Show access package catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Get the state and visibility of catalog {catalog}. slots: catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}'].delete update: x-apievangelist-phrasing: intent: Delete an access package catalog effect: destructive questions: - Can I delete an access package catalog I no longer use? - What's involved in permanently removing a catalog? instructions: - text: Delete access package catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Permanently remove catalog {catalog}. slots: catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}'].patch update: x-apievangelist-phrasing: intent: Update an access package catalog effect: write questions: - Can I rename a catalog or change its description? - Is it possible to toggle a catalog's external visibility later? instructions: - text: Rename catalog {catalog} to {name}. slots: catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Update catalog {catalog} description to {description}. slots: catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/accessPackages'].get update: x-apievangelist-phrasing: intent: List access packages in a catalog effect: read questions: - Which access packages live in a specific catalog? - Can I page through a catalog's access packages with a filter? instructions: - text: List access packages in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Show the first {top} access packages of catalog {catalog}. slots: top: query.$top catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/accessPackages/{accessPackage-id}'].get update: x-apievangelist-phrasing: intent: Get an access package within a catalog effect: read questions: - Can I read one access package through the catalog that holds it? - What does a specific package inside a catalog contain? instructions: - text: Show access package {package} from catalog {catalog}. slots: package: path.accessPackage-id catalog: path.accessPackageCatalog-id - text: Get package {package} as listed in catalog {catalog}. slots: package: path.accessPackage-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/accessPackages/$count'].get update: x-apievangelist-phrasing: intent: Count access packages in a catalog effect: read questions: - How many access packages does a catalog hold? - Can I count a catalog's packages that match a filter? instructions: - text: Count access packages in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Count packages in catalog {catalog} matching {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/customWorkflowExtensions'].get update: x-apievangelist-phrasing: intent: List a catalog's custom workflow extensions effect: read questions: - Which custom workflow extensions are registered in a catalog? - Can I tell whether each extension runs on requests or on assignments? instructions: - text: List custom workflow extensions in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Show the Logic App callouts configured for catalog {catalog}. slots: catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/customWorkflowExtensions'].post update: x-apievangelist-phrasing: intent: Add a custom workflow extension to a catalog effect: write questions: - How do I register a custom workflow extension that calls out to my endpoint? - What endpoint and authentication settings does a new catalog extension need? instructions: - text: Create custom workflow extension {name} in catalog {catalog}. slots: name: requestBody.displayName catalog: path.accessPackageCatalog-id - text: Add extension {name} to catalog {catalog} calling endpoint {endpoint}. slots: name: requestBody.displayName catalog: path.accessPackageCatalog-id endpoint: requestBody.endpointConfiguration method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/customWorkflowExtensions/{customCalloutExtension-id}'].get update: x-apievangelist-phrasing: intent: Get a catalog's custom workflow extension effect: read questions: - What endpoint does one custom workflow extension call? - Where do I read the authentication settings of a single catalog extension? instructions: - text: Show custom workflow extension {extension} in catalog {catalog}. slots: extension: path.customCalloutExtension-id catalog: path.accessPackageCatalog-id - text: Get endpoint settings of extension {extension} from catalog {catalog}. slots: extension: path.customCalloutExtension-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/customWorkflowExtensions/{customCalloutExtension-id}'].delete update: x-apievangelist-phrasing: intent: Delete a custom workflow extension effect: destructive questions: - Can I delete a custom workflow extension that policies still reference? - What must I detach before removing a catalog extension? instructions: - text: Delete custom workflow extension {extension} from catalog {catalog}. slots: extension: path.customCalloutExtension-id catalog: path.accessPackageCatalog-id - text: Remove unused extension {extension} out of catalog {catalog}. slots: extension: path.customCalloutExtension-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/customWorkflowExtensions/{customCalloutExtension-id}'].patch update: x-apievangelist-phrasing: intent: Update a custom workflow extension effect: write questions: - Can I point an existing custom workflow extension at a new endpoint? - Is it possible to rename a catalog extension without recreating it? instructions: - text: Rename custom workflow extension {extension} in catalog {catalog} to {name}. slots: extension: path.customCalloutExtension-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Change the endpoint of extension {extension} in catalog {catalog} to {endpoint}. slots: extension: path.customCalloutExtension-id catalog: path.accessPackageCatalog-id endpoint: requestBody.endpointConfiguration method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/customWorkflowExtensions/$count'].get update: x-apievangelist-phrasing: intent: Count a catalog's custom workflow extensions effect: read questions: - How many custom workflow extensions does a catalog have? - Can I count only the catalog extensions matching a filter? instructions: - text: Count custom workflow extensions in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Count extensions of catalog {catalog} matching {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles'].get update: x-apievangelist-phrasing: intent: List resource roles in a catalog effect: read questions: - Which roles can I pick from a resource added to a catalog? - Before building a role scope, how do I find the available resource roles? instructions: - text: List resource roles in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: List roles in catalog {catalog} matching {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles'].post update: x-apievangelist-phrasing: intent: Add a resource role to a catalog effect: write questions: - Can I add a resource role entry directly to a catalog? - What origin ID and system does a new catalog resource role need? instructions: - text: Create resource role {name} in catalog {catalog}. slots: name: requestBody.displayName catalog: path.accessPackageCatalog-id - text: Add a role with origin ID {originId} to catalog {catalog}. slots: originId: requestBody.originId catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a resource role in a catalog effect: read questions: - What are the details of one resource role in a catalog? - Which origin system does a given catalog role come from? instructions: - text: Show resource role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get origin details of catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a resource role from a catalog effect: destructive questions: - Can I delete a resource role entry from a catalog? - What happens when I drop a role from a catalog's role list? instructions: - text: Delete resource role {role} from catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Drop catalog role {role} out of catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource role in a catalog effect: write questions: - Can I rename a resource role stored in a catalog? - Is it possible to edit a catalog role's description? instructions: - text: Rename resource role {role} in catalog {catalog} to {name}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set the description of catalog role {role} in catalog {catalog} to {description}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource behind a catalog role effect: read questions: - Which resource does a catalog's resource role belong to? - Can I look up the app or group a catalog role is defined on? instructions: - text: Show the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get the resource that role {role} of catalog {catalog} grants access to. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource behind a catalog role effect: destructive questions: - Can I delete the resource reference hanging off a catalog role? - What happens if I remove the resource a catalog role points to? instructions: - text: Delete the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Detach the underlying resource from role {role} of catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource behind a catalog role effect: write questions: - Can I rename the resource that a catalog role hangs off? - Is it possible to edit the resource description through a catalog role? instructions: - text: Rename the resource behind catalog role {role} in catalog {catalog} to {name}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set the description of catalog role {role}'s resource in catalog {catalog} to {description}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a catalog role's resource effect: read questions: - Which environment is the resource behind a catalog role hosted in? - Can I see the origin environment for a catalog role's resource? instructions: - text: Show the environment of the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get hosting environment details for role {role}'s resource in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource behind a catalog role effect: write questions: - Can I refresh the resource a catalog role belongs to? - Is there a refresh action for the resource reached from a catalog role? instructions: - text: Refresh the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Trigger a refresh on role {role}'s underlying resource in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles on a catalog role's resource effect: read questions: - What other roles does the resource behind a catalog role offer? - Can I list sibling roles of a catalog role on the same resource? instructions: - text: List roles on the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Show sibling roles offered by role {role}'s resource in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a catalog role's resource effect: write questions: - Can I add a new role to the resource that a catalog role hangs off? - What origin ID does a role added under a catalog role's resource need? instructions: - text: Add role {name} to the resource behind catalog role {role} in catalog {catalog}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Create a sibling role with origin ID {originId} on role {role}'s resource in catalog {catalog}. slots: originId: requestBody.originId role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/roles/{accessPackageResourceRole-id1}'].get update: x-apievangelist-phrasing: intent: Get a sibling role on a catalog role's resource effect: read questions: - Can I read one specific sibling role on a catalog role's resource? - Where do I see the origin of another role on the same resource as a catalog role? instructions: - text: Show sibling role {role1} on the resource behind catalog role {role} in catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get role {role1} from catalog role {role}'s resource in catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/roles/{accessPackageResourceRole-id1}'].delete update: x-apievangelist-phrasing: intent: Delete a sibling role on a catalog role's resource effect: destructive questions: - Can I remove a sibling role from the resource behind a catalog role? - What happens if I delete another role on a catalog role's resource? instructions: - text: Delete sibling role {role1} on the resource behind catalog role {role} in catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Remove role {role1} from catalog role {role}'s resource in catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/roles/{accessPackageResourceRole-id1}'].patch update: x-apievangelist-phrasing: intent: Update a sibling role on a catalog role's resource effect: write questions: - Can I rename a sibling role on the resource behind a catalog role? - Is it possible to edit another role's description via a catalog role's resource? instructions: - text: Rename sibling role {role1} behind catalog role {role} in catalog {catalog} to {name}. slots: role1: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set description {description} on role {role1} of catalog role {role}'s resource, catalog {catalog}. slots: description: requestBody.description role1: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles on a catalog role's resource effect: read questions: - How many roles does the resource behind a catalog role expose? - Can I count sibling roles on a catalog role's resource with a filter? instructions: - text: Count roles on the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Tally sibling roles of catalog role {role} in catalog {catalog} matching {filter}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes on a catalog role's resource effect: read questions: - Which scopes does the resource behind a catalog role define? - Can I see the sites or subsets a catalog role's resource is split into? instructions: - text: List scopes on the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Show every scope of role {role}'s resource in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a catalog role's resource effect: write questions: - Can I add a scope to the resource behind a catalog role? - Is it possible to mark a new scope on a catalog role's resource as the root scope? instructions: - text: Add a new scope called {name} on the resource behind catalog role {role}, catalog {catalog}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Create a scope with root flag {isRoot} on role {role}'s resource in catalog {catalog}. slots: isRoot: requestBody.isRootScope role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope on a catalog role's resource effect: read questions: - Can I read one scope on the resource behind a catalog role? - Is a given scope of a catalog role's resource the root scope? instructions: - text: Show scope {scope} on the resource behind catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get scope {scope} of role {role}'s resource in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope on a catalog role's resource effect: destructive questions: - Can I delete a scope from the resource behind a catalog role? - What happens if I drop a scope off a catalog role's resource? instructions: - text: Delete scope {scope} on the resource behind catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Drop scope {scope} from role {role}'s resource in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a catalog role's resource effect: write questions: - Can I rename a scope on the resource behind a catalog role? - Is there a way to change a scope's description through a catalog role? instructions: - text: Rename scope {scope} behind catalog role {role} in catalog {catalog} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Change scope {scope}'s description to {description} on catalog role {role}'s resource in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource of a scope under a catalog role effect: read questions: - Which resource does a scope under a catalog role point back to? - Can I read the resource attached to one scope reached from a catalog role? instructions: - text: Show the resource of scope {scope} under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get scope {scope}'s parent resource via catalog role {role}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a scope under a catalog role effect: destructive questions: - Can I delete the resource link on a scope under a catalog role? - What happens if a scope reached from a catalog role loses its resource? instructions: - text: Delete the resource of scope {scope} under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Detach scope {scope}'s resource reached through catalog role {role}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource of a scope under a catalog role effect: write questions: - Can I rename the resource linked from a scope under a catalog role? - Is editing a resource through a catalog role's scope possible? instructions: - text: Rename the resource of scope {scope} under catalog role {role} in catalog {catalog} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Update scope {scope}'s resource description to {description} via catalog role {role}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment of a scope's resource under a catalog role effect: read questions: - Which environment hosts the resource of a scope under a catalog role? - Can I check the origin environment through a catalog role's scope? instructions: - text: Show the environment of scope {scope}'s resource under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get hosting environment for scope {scope} reached via catalog role {role}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a scope's resource under a catalog role effect: write questions: - Can I refresh the resource of a scope reached from a catalog role? - Is there a refresh action through a catalog role's scope path? instructions: - text: Refresh the resource of scope {scope} under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Trigger a refresh on scope {scope}'s resource via catalog role {role}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a scope's resource under a catalog role effect: read questions: - Which roles does the resource of a scope under a catalog role offer? - Can I list roles reached through a catalog role and one of its scopes? instructions: - text: List roles of scope {scope}'s resource under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Show roles on the resource of scope {scope} via catalog role {role}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a scope's resource under a catalog role effect: write questions: - Can I add a role to the resource of a scope reached via a catalog role? - What fields does a role created through a catalog role's scope need? instructions: - text: Add role {name} to scope {scope}'s resource under catalog role {role} in catalog {catalog}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Create role with origin ID {originId} on scope {scope}'s resource via catalog role {role}, catalog {catalog}. slots: originId: requestBody.originId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id1}'].get update: x-apievangelist-phrasing: intent: Get a role of a scope's resource under a catalog role effect: read questions: - Can I read a single role on the resource of a scope under a catalog role? - Where do I see one role reached through a catalog role's scope? instructions: - text: Show role {role1} of scope {scope}'s resource under catalog role {role} in catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get role {role1} via scope {scope} and catalog role {role}, catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id1}'].delete update: x-apievangelist-phrasing: intent: Delete a role of a scope's resource under a catalog role effect: destructive questions: - Can I delete a role on the resource of a scope under a catalog role? - What happens if I remove a role reached via a catalog role's scope? instructions: - text: Delete role {role1} of scope {scope}'s resource under catalog role {role} in catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Remove role {role1} reached through scope {scope} of catalog role {role}, catalog {catalog}. slots: role1: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id1}'].patch update: x-apievangelist-phrasing: intent: Update a role of a scope's resource under a catalog role effect: write questions: - Can I rename a role on the resource of a scope under a catalog role? - Is editing a role's description via a catalog role's scope supported? instructions: - text: Rename role {role1} of scope {scope}'s resource under catalog role {role} in catalog {catalog} to {name}. slots: role1: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set description {description} on role {role1} via scope {scope}, catalog role {role}, catalog {catalog}. slots: description: requestBody.description role1: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a scope's resource under a catalog role effect: read questions: - How many roles does the resource of a scope under a catalog role have? - Can I count roles reached via a catalog role's scope using a filter? instructions: - text: Count roles of scope {scope}'s resource under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Tally roles via scope {scope} of catalog role {role} in catalog {catalog} matching {filter}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions for a scope under a catalog role effect: read questions: - Which BYOD upload sessions exist for a scope under a catalog role? - Can I page through data upload sessions reached via a catalog role's scope? instructions: - text: List upload sessions for scope {scope} under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Show the first {top} BYOD sessions of scope {scope}, catalog role {role}, catalog {catalog}. slots: top: query.$top scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session for a scope under a catalog role effect: write questions: - How do I start uploading external access data for a scope under a catalog role? - Can a new upload session carry my own reference ID when opened through a catalog role's scope? instructions: - text: Start a BYOD upload session for scope {scope} under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Open an upload session with reference {ref} on scope {scope} via catalog role {role}, catalog {catalog}. slots: ref: requestBody.referenceId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session for a scope under a catalog role effect: read questions: - What is the status of one BYOD upload session on a scope under a catalog role? - Has a given upload session reached through a catalog role's scope finished? instructions: - text: Show upload session {session} for scope {scope} under catalog role {role} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Check if session {session} is done, via scope {scope} and catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session for a scope under a catalog role effect: destructive questions: - Can I delete a BYOD upload session sitting on a scope under a catalog role? - What's the way to throw away an abandoned upload reached through a catalog role's scope? instructions: - text: Delete upload session {session} for scope {scope} under catalog role {role} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Discard abandoned BYOD session {session} via scope {scope}, catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session for a scope under a catalog role effect: write questions: - Can I flag an upload session on a catalog role's scope as finished? - Is it possible to change the reference ID of an existing scope upload session under a catalog role? instructions: - text: 'Mark upload session {session} on scope {scope} under catalog role {role} as done: {done}, catalog {catalog}.' slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id done: requestBody.isUploadDone catalog: path.accessPackageCatalog-id - text: Set reference {ref} on session {session} via scope {scope}, catalog role {role}, catalog {catalog}. slots: ref: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload session under a catalog role's scope effect: read questions: - Which files were uploaded in a BYOD session on a scope under a catalog role? - Can I list the data files of an upload session reached via a catalog role's scope? instructions: - text: List files uploaded in session {session} for scope {scope} under catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Show every file in BYOD session {session}, scope {scope}, catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file's details in a scope upload session effect: read questions: - What metadata is stored for one file in an upload session under a catalog role's scope? - Can I inspect a single uploaded file reached via a catalog role and scope? instructions: - text: Show file {file} metadata from session {session}, scope {scope}, catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get details of uploaded file {file} in session {session} via scope {scope}, catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a scope upload session effect: read questions: - How can I download the raw bytes of a file uploaded under a catalog role's scope? - Is the actual content of a BYOD file on a catalog role scope retrievable? instructions: - text: Download file {file} content from session {session}, scope {scope}, catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Fetch the raw data of file {file}, session {session}, scope {scope} under catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file's content in a scope upload session effect: write questions: - Can I overwrite the data of a file already uploaded under a catalog role's scope? - Is replacing a BYOD file's bytes through a catalog role scope supported? instructions: - text: Replace the bytes of file {file} in session {session}, scope {scope}, catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Overwrite stored data for file {file} of session {session} via scope {scope} and catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase a file's content in a scope upload session effect: destructive questions: - Can I wipe the stored content of a file uploaded under a catalog role's scope? - What happens if I erase a BYOD file's data on a catalog role scope? instructions: - text: Erase the stored content of file {file} in session {session}, scope {scope}, catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Wipe data of uploaded file {file}, session {session}, via scope {scope} under catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a scope upload session effect: read questions: - How many files does an upload session on a catalog role's scope hold? - Can I count the uploaded files in a scope session under a catalog role with a filter? instructions: - text: Count files in session {session} for scope {scope} under catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Tally uploaded files of session {session}, scope {scope}, catalog role {role}, catalog {catalog} matching {filter}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file into a scope upload session effect: write questions: - How do I push a data file into a BYOD session on a scope under a catalog role? - Can I send external access data into an open upload session via a catalog role's scope? instructions: - text: Upload a file into session {session} for scope {scope} under catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Push a new data file to BYOD session {session} via scope {scope}, catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions for a scope under a catalog role effect: read questions: - How many upload sessions exist for a scope under a catalog role? - Can I count BYOD sessions on a catalog role's scope matching a filter? instructions: - text: Count upload sessions for scope {scope} under catalog role {role} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Tally BYOD sessions of scope {scope}, catalog role {role}, catalog {catalog} matching {filter}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes on a catalog role's resource effect: read questions: - How many scopes does the resource behind a catalog role define? - Can I count the scopes of a catalog role's resource using a filter? instructions: - text: Count scopes on the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Tally scopes of catalog role {role}'s resource in catalog {catalog} matching {filter}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions behind a catalog role effect: read questions: - Which BYOD upload sessions exist on the resource behind a catalog role? - Can I page through external data uploads for a catalog role's resource? instructions: - text: List upload sessions on the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Show the first {top} BYOD sessions behind catalog role {role}, catalog {catalog}. slots: top: query.$top role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session behind a catalog role effect: write questions: - How do I begin a Bring Your Own Data upload for the resource behind a catalog role? - Can I tag a new upload session behind a catalog role with my own reference? instructions: - text: Start a BYOD upload session on the resource behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Open an upload session with reference {ref} behind catalog role {role}, catalog {catalog}. slots: ref: requestBody.referenceId role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session behind a catalog role effect: read questions: - Starting from a catalog rather than an access package, what's the state of one BYOD upload on a role's resource? - Is a specific BYOD session behind a catalog role marked as done? instructions: - text: Show upload session {session} behind catalog role {role} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Check progress of BYOD session {session} on catalog role {role}'s resource, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session behind a catalog role effect: destructive questions: - Can I delete an upload session on the resource behind a catalog role? - What's the way to discard a stale BYOD session for a catalog role's resource? instructions: - text: Delete upload session {session} behind catalog role {role} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Discard stale BYOD session {session} on catalog role {role}'s resource, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session behind a catalog role effect: write questions: - Can I mark an upload session behind a catalog role as complete? - Is it possible to set a new reference on a BYOD session for a catalog role's resource? instructions: - text: 'Mark upload session {session} behind catalog role {role} as done: {done}, catalog {catalog}.' slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id done: requestBody.isUploadDone catalog: path.accessPackageCatalog-id - text: Set reference {ref} on BYOD session {session} of catalog role {role}'s resource, catalog {catalog}. slots: ref: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload session behind a catalog role effect: read questions: - Which files have been uploaded to a BYOD session behind a catalog role? - Can I list the files of an upload on a catalog role's resource? instructions: - text: List files in upload session {session} behind catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Show uploaded files of BYOD session {session} on catalog role {role}'s resource, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file's details behind a catalog role effect: read questions: - What details are kept for one file in an upload session behind a catalog role? - Can I inspect a single BYOD file on a catalog role's resource? instructions: - text: Show file {file} metadata in session {session} behind catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Get details of uploaded file {file}, session {session}, on catalog role {role}'s resource, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file uploaded behind a catalog role effect: read questions: - How can I download a file's raw data from an upload behind a catalog role? - Is the content of a BYOD file on a catalog role's resource downloadable? instructions: - text: Download file {file} content from session {session} behind catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Fetch raw data of file {file} in session {session} on catalog role {role}'s resource, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file's content behind a catalog role effect: write questions: - Can I overwrite a file's bytes in an upload session behind a catalog role? - Is replacing uploaded BYOD data on a catalog role's resource allowed? instructions: - text: Replace the bytes of file {file} in session {session} behind catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Overwrite stored data for file {file}, session {session}, on catalog role {role}'s resource, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase a file's content behind a catalog role effect: destructive questions: - Can I wipe the content of a file uploaded behind a catalog role? - What happens when I erase a BYOD file's data on a catalog role's resource? instructions: - text: Erase the stored content of file {file} in session {session} behind catalog role {role}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Wipe data of file {file}, session {session}, on catalog role {role}'s resource, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload session behind a catalog role effect: read questions: - How many files are in an upload session behind a catalog role? - Can I count the files of a BYOD session on a catalog role's resource with a filter? instructions: - text: Count files in session {session} behind catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Tally files of BYOD session {session} on catalog role {role}'s resource, catalog {catalog}, matching {filter}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file behind a catalog role effect: write questions: - How do I upload a data file into a BYOD session behind a catalog role? - Can I add external access data to an open upload on a catalog role's resource? instructions: - text: Upload a file into session {session} behind catalog role {role}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Push a data file to BYOD session {session} on catalog role {role}'s resource, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions behind a catalog role effect: read questions: - How many upload sessions exist on the resource behind a catalog role? - Can I count BYOD sessions for a catalog role's resource matching a filter? instructions: - text: Count upload sessions behind catalog role {role} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id - text: Tally BYOD sessions on catalog role {role}'s resource, catalog {catalog}, matching {filter}. slots: role: path.accessPackageResourceRole-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceRoles/$count'].get update: x-apievangelist-phrasing: intent: Count resource roles in a catalog effect: read questions: - How many resource roles does a catalog contain? - Can I count a catalog's resource roles that match a filter? instructions: - text: Count resource roles in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Count roles in catalog {catalog} matching {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources'].get update: x-apievangelist-phrasing: intent: List resources in a catalog effect: read questions: - Which apps, groups and sites have been added to an access package catalog? - Can I filter a catalog's resources by origin system? instructions: - text: List resources in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: List catalog {catalog} resources matching {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources'].post update: x-apievangelist-phrasing: intent: Add a resource entry to a catalog effect: write questions: - Can I add a resource record straight into a catalog? - What origin ID should a new catalog resource entry carry? instructions: - text: Create resource {name} in catalog {catalog}. slots: name: requestBody.displayName catalog: path.accessPackageCatalog-id - text: Add a resource with origin ID {originId} to catalog {catalog}. slots: originId: requestBody.originId catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}'].get update: x-apievangelist-phrasing: intent: Get a resource in a catalog effect: read questions: - What are the details of one resource added to a catalog? - Which origin system does a specific catalog resource come from? instructions: - text: Show catalog resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get origin details of resource {resource} from catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}'].delete update: x-apievangelist-phrasing: intent: Delete a resource from a catalog effect: destructive questions: - Can I remove a resource from an access package catalog? - What happens to packages when a catalog resource is deleted? instructions: - text: Delete catalog resource {resource} from catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Remove resource {resource} out of catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource in a catalog effect: write questions: - Can I rename a resource that's already in a catalog? - Is it possible to update a catalog resource's description? instructions: - text: Rename catalog resource {resource} in catalog {catalog} to {name}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set the description of resource {resource} in catalog {catalog} to {description}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a catalog resource effect: read questions: - Which environment is a catalog resource hosted in? - Can I see the origin environment recorded for a catalog resource? instructions: - text: Show the environment of catalog resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get hosting environment for resource {resource}, catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a catalog resource effect: write questions: - Can I refresh a resource that was added to a catalog? - Is there an action to refresh one catalog resource directly? instructions: - text: Refresh catalog resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Trigger a refresh of resource {resource} within catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles'].get update: x-apievangelist-phrasing: intent: List roles of a catalog resource effect: read questions: - Which roles does a resource in a catalog offer? - Can I list the assignable roles of one catalog resource? instructions: - text: List roles of catalog resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show assignable roles for resource {resource}, catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a catalog resource effect: write questions: - Can I add a role to a resource in a catalog? - What origin ID does a new role on a catalog resource need? instructions: - text: Add role {name} to catalog resource {resource} in catalog {catalog}. slots: name: requestBody.displayName resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Create a role with origin ID {originId} for resource {resource}, catalog {catalog}. slots: originId: requestBody.originId resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role of a catalog resource effect: read questions: - Can I read one role defined on a catalog resource? - Where do I see a catalog resource role's origin system? instructions: - text: Show role {role} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get origin info for role {role} on resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role of a catalog resource effect: destructive questions: - Is it possible to strip one role off a specific resource in my catalog? - What happens when a role is removed from a resource in a catalog? instructions: - text: Delete role {role} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Remove role {role} from resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role of a catalog resource effect: write questions: - Can I rename a role on a catalog resource? - Is updating the description of a catalog resource role possible? instructions: - text: Give role {role} on resource {resource} of catalog {catalog} the new name {name}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Update the description of role {role} for resource {resource} in catalog {catalog} to {description}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource linked to a catalog resource role effect: read questions: - Which resource is linked back from a role of a catalog resource? - Can I navigate from a catalog resource's role to its linked resource? instructions: - text: Show the resource linked to role {role} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get role {role}'s linked resource for resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a catalog resource role effect: destructive questions: - Can I delete the linked resource on a role of a catalog resource? - What happens if a catalog resource's role loses its linked resource? instructions: - text: Delete the resource linked to role {role} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Detach role {role}'s linked resource from resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource linked to a catalog resource role effect: write questions: - Can I rename the linked resource through a catalog resource's role? - Is it possible to edit a linked resource's description via its role? instructions: - text: Rename the resource linked to role {role} of catalog resource {resource} in catalog {catalog} to {name}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set description {description} on role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: description: requestBody.description role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment of a role's linked resource effect: read questions: - Which environment hosts the resource linked to a catalog resource's role? - Can I see origin environment details through a role's linked resource? instructions: - text: Show hosting environment details for role {role}'s linked resource on catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Look up where the resource linked to role {role} of {resource} is hosted, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a role's linked resource effect: write questions: - Can I refresh the linked resource reached from a catalog resource's role? - Is there a refresh action on a role's linked resource? instructions: - text: Refresh the resource linked to role {role} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Trigger a refresh via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes on a role's linked resource effect: read questions: - Which scopes exist on the resource linked to a catalog resource's role? - Can I list scopes reached through a role's linked resource? instructions: - text: List scopes on the resource linked to role {role} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show scopes via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a role's linked resource effect: write questions: - Can I add a scope to the resource linked to a catalog resource's role? - Is it possible to create a root scope through a role's linked resource? instructions: - text: Add a new scope called {name} on the resource linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Create a scope with root flag {isRoot} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: isRoot: requestBody.isRootScope role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope on a role's linked resource effect: read questions: - Can I read one scope on the resource linked to a catalog resource's role? - Is a given scope on a role's linked resource the root scope? instructions: - text: Show scope {scope} on the resource linked to role {role} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get scope {scope} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope on a role's linked resource effect: destructive questions: - Can I delete a scope from the resource linked to a catalog resource's role? - What happens if I drop a scope on a role's linked resource? instructions: - text: Delete scope {scope} on the resource linked to role {role} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Drop scope {scope} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a role's linked resource effect: write questions: - Can I rename a scope on the resource linked to a catalog resource's role? - Is changing a scope's description through a role's linked resource supported? instructions: - text: Rename scope {scope} on role {role}'s linked resource, catalog resource {resource}, catalog {catalog}, to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Change scope {scope}'s description to {description} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource of a scope inside a resource role effect: read questions: - Which resource does a scope inside a catalog resource's role point to? - Can I navigate from a role's scope back to its resource? instructions: - text: Show the resource of scope {scope} inside role {role} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get scope {scope}'s resource inside role {role}, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a scope inside a resource role effect: destructive questions: - Can I delete the resource link of a scope inside a catalog resource's role? - What happens if a scope nested inside a role loses its resource? instructions: - text: Delete the resource of scope {scope} inside role {role} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Detach scope {scope}'s resource nested inside role {role}, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource of a scope inside a resource role effect: write questions: - Can I rename the resource of a scope inside a catalog resource's role? - Is editing a resource description via a role's nested scope possible? instructions: - text: Rename the resource of scope {scope} inside role {role} of catalog resource {resource} in catalog {catalog} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set description {description} on scope {scope}'s resource nested inside role {role}, resource {resource}, catalog {catalog}. slots: description: requestBody.description scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment of a scope's resource inside a role effect: read questions: - Which environment hosts the resource of a scope inside a catalog resource's role? - Can I see origin environment details via a role's nested scope? instructions: - text: Show the environment of scope {scope}'s resource inside role {role} of catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get hosting environment for scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a scope's resource inside a role effect: write questions: - Can I refresh the resource of a scope inside a catalog resource's role? - Is there a refresh action through a role's nested scope? instructions: - text: Refresh the resource of scope {scope} inside role {role} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Trigger a refresh on scope {scope}'s resource nested inside role {role}, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions for a scope inside a resource role effect: read questions: - Which BYOD upload sessions exist for a scope inside a catalog resource's role? - Can I page through uploads reached via a role and its nested scope? instructions: - text: List upload sessions for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show the first {top} BYOD sessions of scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: top: query.$top scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session for a scope inside a resource role effect: write questions: - How do I open a data upload for a scope nested inside a catalog resource's role? - Can a BYOD session started through a role's nested scope carry my reference ID? instructions: - text: Start a BYOD upload session for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Open a session with reference {ref} on scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session for a scope inside a resource role effect: read questions: - What state is a BYOD session in for a scope inside a catalog resource's role? - Has one upload on a role's nested scope been marked done? instructions: - text: Show upload session {session} for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Check progress of session {session}, scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session for a scope inside a resource role effect: destructive questions: - Can I delete a BYOD session on a scope inside a catalog resource's role? - What's the way to throw out an abandoned upload on a role's nested scope? instructions: - text: Delete upload session {session} for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Discard session {session} on scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session for a scope inside a resource role effect: write questions: - Can I mark an upload on a scope inside a catalog resource's role as complete? - Is changing the reference of a BYOD session on a role's nested scope allowed? instructions: - text: 'Mark session {session} for scope {scope} inside role {role} as done: {done}, resource {resource}, catalog {catalog}.' slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id done: requestBody.isUploadDone resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Set reference {ref} on session {session}, scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a session for a scope inside a resource role effect: read questions: - Which files sit in a BYOD session for a scope inside a catalog resource's role? - Can I list uploaded files through a role's nested scope session? instructions: - text: List files in session {session} for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show uploaded files of session {session}, scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get file details for a scope inside a resource role effect: read questions: - What metadata is kept for a file uploaded to a scope inside a catalog resource's role? - Can I inspect one BYOD file through a role's nested scope? instructions: - text: Show file {file} metadata in session {session}, scope {scope} inside role {role}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get details of file {file}, session {session}, scope {scope} nested inside role {role} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file for a scope inside a resource role effect: read questions: - How can I download a BYOD file's raw bytes on a scope inside a catalog resource's role? - Is file content from a role's nested scope session downloadable? instructions: - text: Download file {file} content from session {session}, scope {scope} inside role {role}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Fetch raw data of file {file}, session {session}, scope {scope} nested inside role {role} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content for a scope inside a resource role effect: write questions: - Can I overwrite a file's bytes on a scope inside a catalog resource's role? - Is replacing BYOD data through a role's nested scope allowed? instructions: - text: Replace the bytes of file {file} in session {session}, scope {scope} inside role {role}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Overwrite data for file {file}, session {session}, scope {scope} nested inside role {role} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase file content for a scope inside a resource role effect: destructive questions: - Can I wipe a file's stored data on a scope inside a catalog resource's role? - What happens if I erase BYOD content through a role's nested scope? instructions: - text: Erase the stored content of file {file}, session {session}, scope {scope} inside role {role}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Wipe data of file {file}, session {session}, scope {scope} nested inside role {role} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files for a scope inside a resource role effect: read questions: - How many files are in a session for a scope inside a catalog resource's role? - Can I count uploaded files on a role's nested scope with a filter? instructions: - text: Count files in session {session} for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally files of session {session}, scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}, matching {filter}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a scope inside a resource role effect: write questions: - How do I upload a data file to a scope inside a catalog resource's role? - Can I push external access data into a session on a role's nested scope? instructions: - text: Upload a file into session {session} for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Push a data file to session {session}, scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions for a scope inside a resource role effect: read questions: - How many upload sessions exist for a scope inside a catalog resource's role? - Is there a filterable session count for a scope nested inside a resource's role? instructions: - text: Count upload sessions for scope {scope} inside role {role} of catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally BYOD sessions of scope {scope} nested inside role {role}, resource {resource}, catalog {catalog}, matching {filter}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes on a role's linked resource effect: read questions: - How many scopes exist on the resource linked to a catalog resource's role? - Can I count scopes via a role's linked resource with a filter? instructions: - text: Count scopes on the resource linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally scopes via role {role}'s linked resource, resource {resource}, catalog {catalog}, matching {filter}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions on a role's linked resource effect: read questions: - Which BYOD upload sessions exist on the resource linked to a catalog resource's role? - Can I page through uploads for a role's linked resource? instructions: - text: List upload sessions linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show the first {top} BYOD sessions via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: top: query.$top role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a role's linked resource effect: write questions: - How do I start a Bring Your Own Data upload through a catalog resource's role? - Can a new session on a role's linked resource carry my reference ID? instructions: - text: Start a BYOD upload session linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Open a session with reference {ref} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session on a role's linked resource effect: read questions: - What status is one BYOD session in on a role's linked resource? - Has an upload reached through a catalog resource's role finished? instructions: - text: Show upload session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Check progress of session {session} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session on a role's linked resource effect: destructive questions: - Can I delete a BYOD session on the resource linked to a catalog resource's role? - What's the way to discard an abandoned upload on a role's linked resource? instructions: - text: Delete upload session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Discard session {session} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session on a role's linked resource effect: write questions: - Can I flag an upload on a role's linked resource as finished? - Is updating the reference on a BYOD session through a catalog resource's role possible? instructions: - text: 'Mark session {session} linked to role {role} as done: {done}, catalog resource {resource}, catalog {catalog}.' slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id done: requestBody.isUploadDone resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Set reference {ref} on session {session} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a session on a role's linked resource effect: read questions: - Which files were uploaded to a session on a role's linked resource? - Can I list BYOD files reached through a catalog resource's role? instructions: - text: List files in session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show uploaded files of session {session} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get file details on a role's linked resource effect: read questions: - What metadata is stored for one BYOD file on a role's linked resource? - Can I inspect a single uploaded file through a catalog resource's role? instructions: - text: Show file {file} metadata in session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get details of file {file}, session {session}, via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file on a role's linked resource effect: read questions: - How do I download a file's raw bytes from a session on a role's linked resource? - Is BYOD file content reachable via a catalog resource's role downloadable? instructions: - text: Download file {file} content from session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Fetch raw data of file {file}, session {session}, via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content on a role's linked resource effect: write questions: - Can I overwrite a file's data in a session on a role's linked resource? - Is replacing BYOD bytes through a catalog resource's role supported? instructions: - text: Replace the bytes of file {file} in session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Overwrite data for file {file}, session {session}, via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase file content on a role's linked resource effect: destructive questions: - Can I wipe a file's stored content on a role's linked resource? - What happens if I erase BYOD data through a catalog resource's role? instructions: - text: Erase the stored content of file {file}, session {session}, linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Wipe data of file {file}, session {session}, via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a session on a role's linked resource effect: read questions: - How many files does a session on a role's linked resource hold? - Can I count BYOD files reached via a catalog resource's role with a filter? instructions: - text: Count files in session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally files of session {session} via role {role}'s linked resource, resource {resource}, catalog {catalog}, matching {filter}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file on a role's linked resource effect: write questions: - How do I upload a data file to a session on a role's linked resource? - Can I push external access data through a catalog resource's role? instructions: - text: Upload a file into session {session} linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Push a data file to session {session} via role {role}'s linked resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a role's linked resource effect: read questions: - How many upload sessions exist on a role's linked resource? - Can I get a filtered tally of uploads through a catalog resource's role? instructions: - text: Count upload sessions linked to role {role} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally BYOD sessions via role {role}'s linked resource, resource {resource}, catalog {catalog}, matching {filter}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a catalog resource effect: read questions: - How many roles does a catalog resource offer? - Can I count a catalog resource's roles matching a filter? instructions: - text: Count roles of catalog resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally roles for resource {resource}, catalog {catalog}, matching {filter}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a catalog resource effect: read questions: - Which scopes, like sites or subsets, does a catalog resource define? - Can I list every scope of one resource in my catalog? instructions: - text: List scopes of catalog resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show every scope defined for resource {resource}, catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a catalog resource effect: write questions: - Can I add a scope to a resource that lives in a catalog? - Is it possible to flag a new catalog resource scope as its root scope? instructions: - text: Add scope {name} to catalog resource {resource} in catalog {catalog}. slots: name: requestBody.displayName resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Create a scope with root flag {isRoot} for resource {resource}, catalog {catalog}. slots: isRoot: requestBody.isRootScope resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope of a catalog resource effect: read questions: - Can I read one scope of a catalog resource? - Is a particular scope on a catalog resource the root one? instructions: - text: Show scope {scope} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get whether scope {scope} of resource {resource} is the root, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope of a catalog resource effect: destructive questions: - Can I delete a scope from a resource in my catalog? - What happens to role scopes when a catalog resource's scope is removed? instructions: - text: Delete scope {scope} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Remove scope {scope} from resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope of a catalog resource effect: write questions: - Can I rename a scope defined on a catalog resource? - Is it possible to edit a catalog resource scope's description? instructions: - text: Rename scope {scope} of catalog resource {resource} in catalog {catalog} to {name}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Update the description of scope {scope} for resource {resource} in catalog {catalog} to {description}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource tied to a catalog resource scope effect: read questions: - Which resource is a scope of a catalog resource tied to? - Can I navigate from a catalog resource's scope back to its resource? instructions: - text: Show the resource tied to scope {scope} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get scope {scope}'s tied resource for resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource tied to a catalog resource scope effect: destructive questions: - Can I delete the resource tied to a scope of a catalog resource? - What happens if a catalog resource's scope loses its tied resource? instructions: - text: Delete the resource tied to scope {scope} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Detach scope {scope}'s tied resource from resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource tied to a catalog resource scope effect: write questions: - Can I rename the resource tied to a catalog resource's scope? - Is editing a tied resource's description through its scope possible? instructions: - text: Rename the resource tied to scope {scope} of catalog resource {resource} in catalog {catalog} to {name}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set description {description} on scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: description: requestBody.description scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment of a scope's tied resource effect: read questions: - Which environment hosts the resource tied to a catalog resource's scope? - Can I see origin environment details via a scope's tied resource? instructions: - text: Show hosting environment details for scope {scope}'s tied resource on catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Look up where the resource tied to scope {scope} of {resource} is hosted, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a scope's tied resource effect: write questions: - Can I refresh the resource tied to a catalog resource's scope? - Is there a refresh action on a scope's tied resource? instructions: - text: Refresh the resource tied to scope {scope} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Trigger a refresh via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles on a scope's tied resource effect: read questions: - Which roles exist on the resource tied to a catalog resource's scope? - Can I list roles reached through a scope's tied resource? instructions: - text: List roles on the resource tied to scope {scope} of catalog resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show roles via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a scope's tied resource effect: write questions: - Can I add a role to the resource tied to a catalog resource's scope? - What origin ID does a role created through a scope's tied resource need? instructions: - text: Add role {name} on the resource tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Create a role with origin ID {originId} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: originId: requestBody.originId scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role on a scope's tied resource effect: read questions: - Can I read one role hanging off a scope's tied resource? - Where do I see a role's origin through a scope's tied resource? instructions: - text: Show role {role} on the resource tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get role {role} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role on a scope's tied resource effect: destructive questions: - Is it possible to drop a single role hanging off a scope's tied resource? - What happens if I remove a role through a scope's tied resource? instructions: - text: Delete role {role} on the resource tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Remove role {role} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a scope's tied resource effect: write questions: - Can I give a new name to a role hanging off a scope's tied resource? - Is changing a role's description through a scope's tied resource supported? instructions: - text: Rename role {role} on scope {scope}'s tied resource, catalog resource {resource}, catalog {catalog}, to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Change role {role}'s description to {description} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id description: requestBody.description scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource of a role beneath a resource scope effect: read questions: - Which resource does a role sitting beneath a resource scope point to? - Is there a path from a role beneath a scope back up to its resource? instructions: - text: Show the resource of role {role} beneath scope {scope} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get role {role}'s resource beneath scope {scope}, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a role beneath a resource scope effect: destructive questions: - Can I unlink the resource from a role sitting beneath a resource scope? - What happens if a role sitting beneath a scope loses its resource? instructions: - text: Delete the resource of role {role} beneath scope {scope} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Detach role {role}'s resource sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource of a role beneath a resource scope effect: write questions: - Can I rename the resource of a role sitting beneath a resource scope? - Is renaming or describing a resource via a role beneath a scope possible? instructions: - text: Rename the resource of role {role} beneath scope {scope} of catalog resource {resource} in catalog {catalog} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set description {description} on role {role}'s resource sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: description: requestBody.description role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment of a role's resource beneath a scope effect: read questions: - Which environment hosts the resource of a role sitting beneath a resource scope? - Where is the hosting environment shown for a role beneath a scope? instructions: - text: Show the environment of role {role}'s resource beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get hosting environment for role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a role's resource beneath a scope effect: write questions: - Can I refresh the resource of a role sitting beneath a resource scope? - Does a role beneath a scope expose a refresh on its resource? instructions: - text: Refresh the resource of role {role} beneath scope {scope} of catalog resource {resource} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Trigger a refresh on role {role}'s resource sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions for a role beneath a resource scope effect: read questions: - Which BYOD upload sessions exist for a role sitting beneath a resource scope? - Can I page through uploads for a role beneath a scope? instructions: - text: List upload sessions for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show the first {top} BYOD sessions of role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: top: query.$top role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session for a role beneath a resource scope effect: write questions: - How do I open a data upload for a role sitting beneath a resource scope? - Will a session opened for a role beneath a scope keep my own reference ID? instructions: - text: Start a BYOD upload session for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Open a session with reference {ref} on role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session for a role beneath a resource scope effect: read questions: - What state is a BYOD session in for a role sitting beneath a resource scope? - Is an upload for a role beneath a scope flagged as finished yet? instructions: - text: Show upload session {session} for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Check progress of session {session}, role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session for a role beneath a resource scope effect: destructive questions: - Can I delete a BYOD session for a role sitting beneath a resource scope? - Is there a cleanup for stale uploads on a role beneath a scope? instructions: - text: Delete upload session {session} for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Discard session {session} on role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session for a role beneath a resource scope effect: write questions: - Can I mark an upload for a role sitting beneath a resource scope as complete? - Is a new reference ID settable on a role-beneath-scope session? instructions: - text: 'Mark session {session} for role {role} beneath scope {scope} as done: {done}, resource {resource}, catalog {catalog}.' slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id done: requestBody.isUploadDone resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Set reference {ref} on session {session}, role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a session for a role beneath a resource scope effect: read questions: - Which files sit in a BYOD session for a role sitting beneath a resource scope? - Can I enumerate uploaded files for a role beneath a scope? instructions: - text: List files in session {session} for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show uploaded files of session {session}, role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get file details for a role beneath a resource scope effect: read questions: - What metadata is kept for a file uploaded for a role sitting beneath a resource scope? - Is one uploaded file inspectable for a role beneath a scope? instructions: - text: Show file {file} metadata in session {session}, role {role} beneath scope {scope}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get details of file {file}, session {session}, role {role} sitting beneath scope {scope} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file for a role beneath a resource scope effect: read questions: - How can I download a BYOD file's raw bytes for a role sitting beneath a resource scope? - Are uploaded file bytes for a role beneath a scope retrievable? instructions: - text: Download file {file} content from session {session}, role {role} beneath scope {scope}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Fetch raw data of file {file}, session {session}, role {role} sitting beneath scope {scope} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content for a role beneath a resource scope effect: write questions: - Can I overwrite a file's bytes for a role sitting beneath a resource scope? - Is swapping in new file data for a role beneath a scope allowed? instructions: - text: Replace the bytes of file {file} in session {session}, role {role} beneath scope {scope}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Overwrite data for file {file}, session {session}, role {role} sitting beneath scope {scope} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase file content for a role beneath a resource scope effect: destructive questions: - Can I wipe a file's stored data for a role sitting beneath a resource scope? - What happens when uploaded content for a role beneath a scope is erased? instructions: - text: Erase the stored content of file {file}, session {session}, role {role} beneath scope {scope}, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Wipe data of file {file}, session {session}, role {role} sitting beneath scope {scope} of {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files for a role beneath a resource scope effect: read questions: - How many files are in a session for a role sitting beneath a resource scope? - Is a filtered file count available for a role beneath a scope? instructions: - text: Count files in session {session} for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally files of session {session}, role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}, matching {filter}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a role beneath a resource scope effect: write questions: - What's the way to send a file into an open session for a role sitting beneath a resource scope? - Can external access data be sent into a session for a role beneath a scope? instructions: - text: Upload a file into session {session} for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Push a data file to session {session}, role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions for a role beneath a resource scope effect: read questions: - How many upload sessions exist for a role sitting beneath a resource scope? - Is there a filterable session count for a role sitting beneath a resource's scope? instructions: - text: Count upload sessions for role {role} beneath scope {scope} of catalog resource {resource}, catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally BYOD sessions of role {role} sitting beneath scope {scope}, resource {resource}, catalog {catalog}, matching {filter}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles on a scope's tied resource effect: read questions: - How many roles exist on the resource tied to a catalog resource's scope? - Can I count roles via a scope's tied resource with a filter? instructions: - text: Count roles on the resource tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally roles via scope {scope}'s tied resource, resource {resource}, catalog {catalog}, matching {filter}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions on a scope's tied resource effect: read questions: - Which BYOD upload sessions exist on the resource tied to a catalog resource's scope? - Can I page through uploads for a scope's tied resource? instructions: - text: List upload sessions tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show the first {top} BYOD sessions via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: top: query.$top scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a scope's tied resource effect: write questions: - How do I start a Bring Your Own Data upload on a scope's tied resource? - Can a new session on a scope's tied resource carry my reference ID? instructions: - text: Start a BYOD upload session tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Open a session with reference {ref} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session on a scope's tied resource effect: read questions: - What status is one BYOD session in on a scope's tied resource? - Has an upload reached through a catalog resource's scope finished? instructions: - text: Show upload session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Check progress of session {session} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session on a scope's tied resource effect: destructive questions: - Can I delete a BYOD session on the resource tied to a catalog resource's scope? - What's the way to discard an abandoned upload on a scope's tied resource? instructions: - text: Delete upload session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Discard session {session} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session on a scope's tied resource effect: write questions: - Can I flag an upload on a scope's tied resource as finished? - Is a new reference settable on a BYOD session tied to a scope? instructions: - text: 'Mark session {session} tied to scope {scope} as done: {done}, catalog resource {resource}, catalog {catalog}.' slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id done: requestBody.isUploadDone resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Set reference {ref} on session {session} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: ref: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a session on a scope's tied resource effect: read questions: - Which files were uploaded to a session on a scope's tied resource? - Can I list BYOD files reached through a catalog resource's scope? instructions: - text: List files in session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show uploaded files of session {session} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get file details on a scope's tied resource effect: read questions: - What metadata is stored for one BYOD file on a scope's tied resource? - Can I inspect a single uploaded file through a catalog resource's scope? instructions: - text: Show file {file} metadata in session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Get details of file {file}, session {session}, via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file on a scope's tied resource effect: read questions: - How do I download a file's raw bytes from a session on a scope's tied resource? - Is BYOD file content reachable via a catalog resource's scope downloadable? instructions: - text: Download file {file} content from session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Fetch raw data of file {file}, session {session}, via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content on a scope's tied resource effect: write questions: - Can I overwrite a file's data in a session on a scope's tied resource? - Is replacing BYOD bytes through a catalog resource's scope supported? instructions: - text: Replace the bytes of file {file} in session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Overwrite data for file {file}, session {session}, via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Erase file content on a scope's tied resource effect: destructive questions: - Can I wipe a file's stored content on a scope's tied resource? - What happens if I erase BYOD data on a scope's tied resource? instructions: - text: Erase the stored content of file {file}, session {session}, tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Wipe data of file {file}, session {session}, via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a session on a scope's tied resource effect: read questions: - How many files does a session on a scope's tied resource hold? - Is a filtered file count available for a session tied to a scope? instructions: - text: Count files in session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tally files of session {session} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}, matching {filter}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file on a scope's tied resource effect: write questions: - How do I upload a data file to a session on a scope's tied resource? - Can I push external access data through a catalog resource's scope? instructions: - text: Upload a file into session {session} tied to scope {scope} of catalog resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Push a data file to session {session} via scope {scope}'s tied resource, resource {resource}, catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a scope's underlying resource effect: read questions: - How many custom data upload sessions exist for the resource behind one scope of a catalog resource? - Can I count upload sessions reached through a catalog resource's scope instead of listing them? instructions: - text: Count the upload sessions on the resource under scope {scope} of resource {resource} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tell me how many upload sessions match {filter} for scope {scope} of catalog resource {resource} in {catalog}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count the scopes of a catalog resource effect: read questions: - How many scopes does a resource in my access package catalog expose? - Can I get just the number of scopes on one catalog resource without fetching them? instructions: - text: Count the scopes on resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Give me the number of scopes on catalog resource {resource} in {catalog} that match {filter}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions for a catalog resource effect: read questions: - Which custom data upload sessions have been opened for a resource in my access package catalog? - Where do I see the upload sessions and their status for a catalog resource with custom-provided data? instructions: - text: List the custom data upload sessions for resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show the first {top} upload sessions on catalog resource {resource} in {catalog}. slots: top: query.$top resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session for a catalog resource effect: write questions: - How do I start a custom data upload session for a resource in an access package catalog? - Can I open a second upload session for the same resource and access review once the first one is complete? instructions: - text: Create a custom data upload session on resource {resource} in catalog {catalog} for reference {reference}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id reference: requestBody.referenceId - text: Open a new upload session for catalog resource {resource} in {catalog} tied to access review instance {reference}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id reference: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get one upload session of a catalog resource effect: read questions: - What is the status and upload progress of a specific upload session on my catalog resource? - Can I check whether all files have been uploaded for one catalog resource upload session? instructions: - text: Get upload session {session} on resource {resource} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show me the status and stats of catalog resource upload session {session} for {resource} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session on a catalog resource effect: destructive questions: - How can I throw away an active upload session so I can start a fresh one for my catalog resource? - What happens to a catalog resource's data upload if I delete its active upload session? instructions: - text: Delete upload session {session} from resource {resource} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Remove the active upload session {session} on catalog resource {resource} in {catalog} so a new one can be created. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session on a catalog resource effect: write questions: - How do I mark a catalog resource upload session as done once every file is in? - Can I change the properties of an existing upload session on a catalog resource? instructions: - text: Mark upload session {session} on resource {resource} in catalog {catalog} as upload done {upload_done}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id upload_done: requestBody.isUploadDone - text: Update catalog resource upload session {session} for {resource} in {catalog} with reference {reference}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id reference: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalog resource upload session effect: read questions: - Which files have already been uploaded into a catalog resource's upload session? - Can I see every file attached to one custom data upload session on my catalog resource? instructions: - text: List the files in upload session {session} of resource {resource} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show files uploaded to session {session} for catalog resource {resource} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file's details from a catalog upload session effect: read questions: - What metadata is stored for one file I uploaded to a catalog resource upload session? - Can I look up a single uploaded file by id inside a catalog resource session? instructions: - text: Get file {file} from upload session {session} on resource {resource} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Show the properties of uploaded file {file} in catalog resource session {session} for {resource} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file's content from a catalog upload session effect: read questions: - How do I download the raw contents of a file uploaded to a catalog resource upload session? - Can I fetch the actual bytes of a custom data file on a catalog resource, not just its metadata? instructions: - text: Download the content of file {file} in session {session} on resource {resource} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Fetch the raw media of uploaded file {file} from catalog resource {resource} session {session} in {catalog}. slots: file: path.customDataProvidedResourceFile-id resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file's content in a catalog upload session effect: write questions: - How do I overwrite the contents of a file already in a catalog resource upload session? - Can I swap out the bytes of an uploaded custom data file on a catalog resource? instructions: - text: Replace the content of file {file} in upload session {session} on resource {resource} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Overwrite uploaded file {file}'s media in catalog resource session {session} for {resource} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete a file's content from a catalog upload session effect: destructive questions: - How do I clear the stored contents of a file in a catalog resource upload session? - Can I wipe an uploaded file's bytes from a catalog resource session if I sent the wrong data? instructions: - text: Delete the content of file {file} in upload session {session} on resource {resource} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Clear the media stored for uploaded file {file} in catalog resource session {session} of {resource} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a catalog resource upload session effect: read questions: - How many files are in one upload session on my catalog resource? - Can I get a file count for a catalog resource upload session without listing the files? instructions: - text: Count the files in upload session {session} on resource {resource} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Tell me how many uploaded files session {session} holds for catalog resource {resource} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file into a catalog resource upload session effect: write questions: - How do I upload a custom data file into an upload session created for a catalog resource? - Can I push another file into an open catalog resource upload session before marking it done? instructions: - text: Upload a file into session {session} on resource {resource} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Send a custom data file to catalog resource {resource} in {catalog} through upload session {session}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/{accessPackageResource-id}/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a catalog resource effect: read questions: - How many upload sessions have been created for one resource in my catalog? - Can I get a quick count of custom data upload sessions for a catalog resource? instructions: - text: Count the upload sessions on resource {resource} in catalog {catalog}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id - text: Give me the number of catalog resource upload sessions for {resource} in {catalog} matching {filter}. slots: resource: path.accessPackageResource-id catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resources/$count'].get update: x-apievangelist-phrasing: intent: Count the resources in a catalog effect: read questions: - How many resources have been added to an access package catalog? - Can I count only the catalog's resources that match a filter, like a given origin system? instructions: - text: Count the resources in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Count resources in access package catalog {catalog} that match {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes'].get update: x-apievangelist-phrasing: intent: List a catalog's resource scopes effect: read questions: - Which resource scopes are available in my access package catalog? - Can I filter an access package catalog's resource scopes by name or origin? instructions: - text: List the resource scopes in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Show resource scopes in access package catalog {catalog} matching {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes'].post update: x-apievangelist-phrasing: intent: Add a resource scope to a catalog effect: write questions: - How do I add a new resource scope to an access package catalog? - Can I mark a scope I add to a catalog as the root scope of its resource? instructions: - text: Add a resource scope named {name} to catalog {catalog}. slots: name: requestBody.displayName catalog: path.accessPackageCatalog-id - text: Create a catalog resource scope in {catalog} for origin id {origin_id} in origin system {origin_system}. slots: catalog: path.accessPackageCatalog-id origin_id: requestBody.originId origin_system: requestBody.originSystem method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a catalog resource scope effect: read questions: - What are the details of one resource scope in my access package catalog? - Can I see whether a particular catalog resource scope is a root scope? instructions: - text: Get resource scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show the display name and origin of catalog resource scope {scope} in {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Remove a resource scope from a catalog effect: destructive questions: - How do I remove a resource scope from an access package catalog? - Can I delete a catalog resource scope that's no longer used by any access package? instructions: - text: Delete resource scope {scope} from catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Remove catalog resource scope {scope} from {catalog} using etag {etag}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a catalog resource scope effect: write questions: - How do I rename or re-describe a resource scope in my access package catalog? - Can I change the origin details on an existing catalog resource scope? instructions: - text: In catalog {catalog}'s own resource scopes list, give scope {scope} the display name {name}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Change the description on catalog-level resource scope {scope} of {catalog} to {description}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource behind a catalog scope effect: read questions: - Which resource does a given resource scope in my catalog belong to? - Can I read the underlying resource's attributes starting from a catalog resource scope? instructions: - text: Get the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show the resource that catalog resource scope {scope} in {catalog} points to. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource from a catalog scope effect: destructive questions: - How do I delete the resource navigation from a resource scope in my catalog? - Can I detach a catalog scope from its underlying resource? instructions: - text: Delete the resource linked to scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Remove the underlying resource from catalog resource scope {scope} in {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource behind a catalog scope effect: write questions: - How do I change the display name of the resource that a catalog scope belongs to? - Can I edit the underlying resource's description while working from a catalog resource scope? instructions: - text: Rename the resource behind scope {scope} in catalog {catalog} to {name}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Update the description of the resource under catalog resource scope {scope} in {catalog} to {description}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a catalog scope's resource effect: read questions: - Which resource environment hosts the resource behind a scope in my catalog? - Can I find the SharePoint environment for a catalog resource scope's resource? instructions: - text: Get the environment of the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show which environment hosts the resource under catalog resource scope {scope} in {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource behind a catalog scope effect: write questions: - How do I refresh the resource that sits behind a resource scope in my catalog? - Can I trigger a refresh of a catalog scope's underlying resource so its details are current? instructions: - text: Refresh the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Run a refresh on the underlying resource of catalog resource scope {scope} in {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a catalog scope's resource effect: read questions: - What roles does the resource behind a catalog resource scope offer? - Can I filter the roles on a catalog scope's resource by display name? instructions: - text: List the roles on the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show roles matching {filter} on the resource under catalog resource scope {scope} in {catalog}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a catalog scope's resource effect: write questions: - How do I create a role on the resource behind a resource scope in my catalog? - Can I set the origin id of a new role on a catalog scope's resource? instructions: - text: Create a role named {name} on the resource behind scope {scope} in catalog {catalog}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Add a role with origin id {origin_id} to the resource under catalog resource scope {scope} in {catalog}. slots: origin_id: requestBody.originId scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role on a catalog scope's resource effect: read questions: - What are the details of one role on the resource behind a catalog scope? - Can I look up a resource role's origin id starting from a catalog resource scope? instructions: - text: Get role {role} on the resource behind scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show role {role}'s name and origin system for the resource under catalog scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role from a catalog scope's resource effect: destructive questions: - How do I delete a role from the resource that a catalog scope belongs to? - Can I remove an obsolete role from a catalog resource scope's underlying resource? instructions: - text: Delete role {role} from the resource behind scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Remove resource role {role} under catalog resource scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a catalog scope's resource effect: write questions: - How do I rename a role on the resource behind a catalog resource scope? - Can I change a role's description on a catalog scope's resource? instructions: - text: Rename role {role} on the resource behind scope {scope} in catalog {catalog} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set role {role}'s description to {description} on the resource under catalog scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id description: requestBody.description scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource a role belongs to, via a catalog scope effect: read questions: - Which resource owns a role that I reached through a catalog resource scope? - Can I walk from a role back to its parent resource inside a catalog scope path? instructions: - text: Get the resource of role {role} under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show the parent resource for role {role} reached from catalog resource scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink a role's resource, via a catalog scope effect: destructive questions: - How do I delete the resource navigation from a role that sits under a catalog scope? - Can I detach a role reached via a catalog resource scope from its parent resource? instructions: - text: Delete the resource link on role {role} under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Remove the parent resource from role {role} reached through catalog resource scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update a role's resource, via a catalog scope effect: write questions: - How do I edit the parent resource of a role that I found under a catalog scope? - Can I rename the resource a role belongs to while navigating from a catalog resource scope? instructions: - text: Starting from catalog resource scope {scope}, change the display name of role {role}'s parent resource in {catalog} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Update the parent resource description for role {role} via catalog scope {scope} in {catalog} to {description}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get a role resource's environment (catalog scope) effect: read questions: - What environment hosts the parent resource of a role under a catalog resource scope? - Can I find the origin environment for a role's resource starting from a catalog scope? instructions: - text: Get the environment of role {role}'s resource under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show the hosting environment for the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a role's resource, via a catalog scope effect: write questions: - How do I refresh the parent resource of a role that sits under a catalog scope? - Can I trigger a refresh on a role's resource while navigating from a catalog resource scope? instructions: - text: Starting from catalog resource scope {scope}, re-sync the parent resource of role {role} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Run a refresh on the parent resource for role {role} reached via catalog scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a role's resource, via a catalog scope effect: read questions: - What scopes does the parent resource of a role under a catalog scope have? - Can I list sibling scopes of a resource by going through one of its roles in a catalog? instructions: - text: List the scopes on role {role}'s resource under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show scopes matching {filter} on the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: filter: query.$filter role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a role's resource, via a catalog scope effect: write questions: - How do I create a scope on the parent resource of a role reached from a catalog scope? - Can I add a root scope to a role's resource through the catalog resource scope path? instructions: - text: Create a scope named {name} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Add a scope with origin id {origin_id} to the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: origin_id: requestBody.originId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id1}'].get update: x-apievangelist-phrasing: intent: Get a scope of a role's resource, via a catalog scope effect: read questions: - What are the details of one scope on a role's parent resource under a catalog scope? - Can I read a nested scope on a role's resource by id from the catalog path? instructions: - text: Get scope {inner_scope} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show nested scope {inner_scope} of the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id1}'].delete update: x-apievangelist-phrasing: intent: Delete a scope of a role's resource, via a catalog scope effect: destructive questions: - How do I delete a nested scope from a role's parent resource under a catalog scope? - Can I remove a scope on a role's resource while navigating through a catalog resource scope? instructions: - text: Delete scope {inner_scope} from role {role}'s resource under scope {scope} in catalog {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Remove nested scope {inner_scope} on the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id1}'].patch update: x-apievangelist-phrasing: intent: Update a scope of a role's resource, via a catalog scope effect: write questions: - How do I rename a nested scope on a role's parent resource under a catalog scope? - Can I change the description of a scope on a role's resource from the catalog path? instructions: - text: Rename scope {inner_scope} on role {role}'s resource under scope {scope} in catalog {catalog} to {name}. slots: inner_scope: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Set nested scope {inner_scope}'s description to {description} for role {role}'s resource via catalog scope {scope} in {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 description: requestBody.description role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a role's resource, via a catalog scope effect: read questions: - How many scopes does a role's parent resource have when reached from a catalog scope? - Can I count the nested scopes on a role's resource without listing them from the catalog path? instructions: - text: Count the scopes on role {role}'s resource under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Tell me the number of nested scopes for the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List role resource upload sessions (catalog scope) effect: read questions: - Which upload sessions exist for the parent resource of a role under a catalog scope? - Can I see custom data upload sessions on a role's resource from the catalog resource scope path? instructions: - text: List upload sessions on role {role}'s resource under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show the first {top} upload sessions for the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: top: query.$top role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open a role resource upload session (catalog scope) effect: write questions: - How do I start an upload session on the parent resource of a role under a catalog scope? - Can I tie a new upload session on a role's resource to an access review reference from the catalog path? instructions: - text: Create an upload session on role {role}'s resource under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Open an upload session for reference {reference} on the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: reference: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get a role resource upload session (catalog scope) effect: read questions: - What is the status of one upload session on a role's parent resource under a catalog scope? - Can I check upload progress for a session on a role's resource via the catalog scope path? instructions: - text: Get upload session {session} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show status of session {session} for the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role resource upload session (catalog scope) effect: destructive questions: - How do I discard an upload session on a role's parent resource under a catalog scope? - Can I delete a role resource's upload session reached through a catalog scope and start over? instructions: - text: Delete upload session {session} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Remove session {session} from the parent resource of role {role} via catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update a role resource upload session (catalog scope) effect: write questions: - How do I mark an upload session done on a role's parent resource under a catalog scope? - Can I edit an upload session on a role's resource through the catalog resource scope path? instructions: - text: Set upload done to {upload_done} on session {session} of role {role}'s resource under scope {scope} in catalog {catalog}. slots: upload_done: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Update session {session} reference to {reference} for role {role}'s parent resource via catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id reference: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a role resource session (catalog scope) effect: read questions: - Which files are in an upload session on a role's parent resource under a catalog scope? - Can I list uploaded files for a role resource session through the catalog scope path? instructions: - text: List files in session {session} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show uploaded files of session {session} for role {role}'s parent resource via catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file in a role resource session (catalog scope) effect: read questions: - What details are stored for one file in a role resource's upload session under a catalog scope? - Can I look up a single uploaded file for a role's parent resource from the catalog scope path? instructions: - text: Get file {file} in session {session} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show file {file} metadata from session {session}, role {role}'s parent resource, catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a role resource session file (catalog scope) effect: read questions: - How do I download the bytes of a file uploaded for a role's parent resource under a catalog scope? - Can I fetch raw file content from a role resource upload session through the catalog scope path? instructions: - text: Download file {file} content from session {session} of role {role}'s resource, scope {scope}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Fetch raw media of {file} in session {session} on role {role}'s parent resource via catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a role resource session file (catalog scope) effect: write questions: - How do I overwrite a file's content in a role resource upload session under a catalog scope? - Can I re-send the bytes of an uploaded file on a role's parent resource from the catalog scope path? instructions: - text: Replace file {file} content in session {session} of role {role}'s resource, scope {scope}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Overwrite media of {file} in session {session} on role {role}'s parent resource via catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear a role resource session file (catalog scope) effect: destructive questions: - How do I delete a file's content from a role resource upload session under a catalog scope? - Can I wipe uploaded bytes for a role's parent resource session reached from a catalog scope? instructions: - text: Delete file {file} content in session {session} of role {role}'s resource, scope {scope}, catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Wipe the stored bytes of {file}, leaving session {session} open, for role {role}'s parent resource under catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a role resource session (catalog scope) effect: read questions: - How many files are in an upload session on a role's parent resource under a catalog scope? - Can I count files in a role resource session from the catalog scope path without listing them? instructions: - text: Count files in session {session} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Tell me how many files session {session} holds for role {role}'s parent resource via catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a role's resource, via a catalog scope effect: write questions: - How do I upload a custom data file to a session on a role's parent resource under a catalog scope? - Can I add another file to a role resource upload session from the catalog scope path? instructions: - text: Upload a file into session {session} on role {role}'s resource under scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Send a custom data file through session {session} to role {role}'s parent resource via catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count role resource upload sessions (catalog scope) effect: read questions: - How many upload sessions exist on a role's parent resource under a catalog scope? - Can I count role resource upload sessions from the catalog scope path? instructions: - text: Count upload sessions on role {role}'s resource under scope {scope} in catalog {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Tell me the number of upload sessions for role {role}'s parent resource via catalog scope {scope} in {catalog}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a catalog scope's resource effect: read questions: - How many roles does the resource behind a catalog resource scope have? - Can I count the roles on a catalog scope's resource that match a filter? instructions: - text: Count the roles on the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Count roles matching {filter} on the resource under catalog resource scope {scope} in {catalog}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a catalog scope's resource effect: read questions: - What other scopes does the resource behind one of my catalog resource scopes expose? - Can I browse all scopes of a resource starting from a single scope in the catalog? instructions: - text: List the scopes of the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show scopes matching {filter} on the underlying resource of catalog resource scope {scope} in {catalog}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a catalog scope's resource effect: write questions: - How do I add another scope to the resource that a catalog resource scope belongs to? - Can I create a root scope on the underlying resource while working from a catalog scope? instructions: - text: Define an additional scope called {name} for the resource that catalog scope {scope} in {catalog} belongs to. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Add a scope from origin system {origin_system} to the underlying resource of catalog resource scope {scope} in {catalog}. slots: origin_system: requestBody.originSystem scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/{accessPackageResourceScope-id1}'].get update: x-apievangelist-phrasing: intent: Get a sibling scope of a catalog scope's resource effect: read questions: - How can I read one particular scope on the resource behind a catalog resource scope? - Is a given scope on a catalog scope's underlying resource marked as its root scope? instructions: - text: Look up sibling scope {inner_scope} of the resource under catalog scope {scope} in {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show details of scope {inner_scope} belonging to the underlying resource of catalog resource scope {scope} in {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/{accessPackageResourceScope-id1}'].delete update: x-apievangelist-phrasing: intent: Delete a sibling scope of a catalog scope's resource effect: destructive questions: - How do I delete a scope from the resource that sits behind a catalog resource scope? - Can I drop an unused scope on a catalog scope's underlying resource? instructions: - text: Drop sibling scope {inner_scope} from the resource that catalog scope {scope} in {catalog} belongs to. slots: inner_scope: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Remove scope {inner_scope} of the underlying resource of catalog resource scope {scope} in {catalog}. slots: inner_scope: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/{accessPackageResourceScope-id1}'].patch update: x-apievangelist-phrasing: intent: Update a sibling scope of a catalog scope's resource effect: write questions: - How do I rename a sibling scope that shares a resource with one of my catalog scopes? - Can I update the description of another scope on a catalog scope's underlying resource? instructions: - text: Give sibling scope {inner_scope} of catalog scope {scope}'s resource in {catalog} the new name {name}. slots: inner_scope: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id name: requestBody.displayName - text: Change the description of scope {inner_scope} on the underlying resource of catalog resource scope {scope} in {catalog} to {description}. slots: inner_scope: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a catalog scope's resource effect: read questions: - How many scopes are on the resource behind a catalog resource scope? - Can I count a catalog scope's underlying resource scopes that match a filter? instructions: - text: Count the scopes of the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Count scopes matching {filter} on the underlying resource of catalog resource scope {scope} in {catalog}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a catalog scope's resource effect: read questions: - Which upload sessions have been opened on the resource behind a catalog resource scope? - Can I see custom data upload sessions for a scope's underlying resource in my catalog? instructions: - text: List upload sessions on the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show the first {top} upload sessions for the underlying resource of catalog resource scope {scope} in {catalog}. slots: top: query.$top scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a catalog scope's resource effect: write questions: - How do I create an upload session on the resource that a catalog scope belongs to? - Can I start a custom data upload for a scope's underlying resource tied to an access review? instructions: - text: Create an upload session on the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Open an upload session for reference {reference} on the underlying resource of catalog resource scope {scope} in {catalog}. slots: reference: requestBody.referenceId scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a catalog scope's resource effect: read questions: - What is the status of an upload session on the resource behind a catalog resource scope? - Can I see an upload session's stats for a catalog scope's underlying resource? instructions: - text: Get upload session {session} on the resource behind scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show status and stats of session {session} on the underlying resource of catalog resource scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a catalog scope's resource effect: destructive questions: - How do I delete an active upload session on the resource behind a catalog scope? - Can I discard a catalog scope resource's upload session so I can begin again? instructions: - text: Delete upload session {session} on the resource behind scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Discard session {session} from the underlying resource of catalog resource scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a catalog scope's resource effect: write questions: - How do I flag an upload session as complete on the resource behind a catalog scope? - Can I change a catalog scope resource's upload session reference after creating it? instructions: - text: Set upload done to {upload_done} on session {session} of the resource behind scope {scope} in catalog {catalog}. slots: upload_done: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Change the reference of session {session} to {reference} on the underlying resource of catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id reference: requestBody.referenceId scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalog scope resource's upload session effect: read questions: - What files are inside an upload session on the resource behind a catalog scope? - Can I list the uploaded files for a catalog scope's underlying resource session? instructions: - text: List files in session {session} on the resource behind scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show uploaded files of session {session} on the underlying resource of catalog resource scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file in a catalog scope resource's upload session effect: read questions: - What details does one uploaded file have in a catalog scope resource's session? - Can I fetch a single file record from an upload session on a catalog scope's resource? instructions: - text: Get file {file} in session {session} on the resource behind scope {scope} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Show metadata of file {file} in session {session} on the underlying resource of catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a catalog scope resource's session effect: read questions: - How do I download a file's bytes from an upload session on a catalog scope's resource? - Can I get the raw content of a custom data file uploaded against a catalog scope's resource? instructions: - text: Download file {file} content from session {session} on the resource behind scope {scope} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Fetch the raw media of {file} in session {session} for the underlying resource of catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file in a catalog scope resource's session effect: write questions: - How do I overwrite a file's content in an upload session on a catalog scope's resource? - Can I upload corrected bytes over an existing file on a catalog scope's underlying resource? instructions: - text: Replace file {file} content in session {session} on the resource behind scope {scope} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Overwrite media of {file} in session {session} for the underlying resource of catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear a file in a catalog scope resource's session effect: destructive questions: - How do I delete the content of an uploaded file on a catalog scope's resource? - Can I wipe a bad file's bytes from a session on a catalog scope's underlying resource? instructions: - text: Delete file {file} content in session {session} on the resource behind scope {scope} in catalog {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Wipe stored bytes of {file} from session {session} on the underlying resource of catalog scope {scope} in {catalog}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a catalog scope resource's session effect: read questions: - How many files have been uploaded to a session on a catalog scope's resource? - Can I get the file count of a catalog scope resource's upload session? instructions: - text: Count files in session {session} on the resource behind scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Tell me how many files session {session} holds for the underlying resource of catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a catalog scope's resource effect: write questions: - How do I upload a custom data file into a session on the resource behind a catalog scope? - Can I keep adding files to an upload session on a catalog scope's underlying resource? instructions: - text: Upload a file into session {session} on the resource behind scope {scope} in catalog {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Push a custom data file through session {session} to the underlying resource of catalog scope {scope} in {catalog}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a catalog scope's resource effect: read questions: - How many upload sessions exist on the resource behind a catalog resource scope? - Can I count upload sessions for a catalog scope's underlying resource by status? instructions: - text: Count upload sessions on the resource behind scope {scope} in catalog {catalog}. slots: scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id - text: Count sessions matching {filter} on the underlying resource of catalog resource scope {scope} in {catalog}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id catalog: path.accessPackageCatalog-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/{accessPackageCatalog-id}/resourceScopes/$count'].get update: x-apievangelist-phrasing: intent: Count a catalog's resource scopes effect: read questions: - How many resource scopes does my access package catalog contain? - Can I count only the root scopes in an access package catalog? instructions: - text: Tally every resource scope registered in catalog {catalog}. slots: catalog: path.accessPackageCatalog-id - text: Count resource scopes in access package catalog {catalog} matching {filter}. slots: catalog: path.accessPackageCatalog-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/catalogs/$count'].get update: x-apievangelist-phrasing: intent: Count access package catalogs effect: read questions: - How many access package catalogs exist in my tenant? - Can I count only the catalogs that match a filter, such as externally visible ones? instructions: - text: Count my access package catalogs. - text: Count access package catalogs matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations'].get update: x-apievangelist-phrasing: intent: List connected organizations effect: read questions: - Which external organizations are connected for entitlement management in my tenant? - Can I search connected organizations by display name? instructions: - text: List all connected organizations. - text: Find connected organizations matching {search}. slots: search: query.$search method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations'].post update: x-apievangelist-phrasing: intent: Create a connected organization effect: write questions: - How do I set up a connected organization so its users can request access packages? - Can I create a connected organization in a proposed state rather than configured? instructions: - text: Create a connected organization named {name} with identity sources {identity_sources}. slots: name: requestBody.displayName identity_sources: requestBody.identitySources - text: Add a connected organization called {name} described as {description} in state {state}. slots: name: requestBody.displayName description: requestBody.description state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}'].get update: x-apievangelist-phrasing: intent: Get a connected organization effect: read questions: - What identity sources and state does one of my connected organizations have? - Where do I see the details of a single connected organization? instructions: - text: Get connected organization {org}. slots: org: path.connectedOrganization-id - text: Show the identity sources and state of connected organization {org}. slots: org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}'].delete update: x-apievangelist-phrasing: intent: Delete a connected organization effect: destructive questions: - How do I remove a connected organization from entitlement management? - Can I delete a connected organization that is no longer a partner? instructions: - text: Delete connected organization {org}. slots: org: path.connectedOrganization-id - text: Remove connected organization {org} using etag {etag}. slots: org: path.connectedOrganization-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}'].patch update: x-apievangelist-phrasing: intent: Update a connected organization effect: write questions: - How do I rename a connected organization or change its description? - Can I switch a connected organization from proposed to configured? instructions: - text: Rename connected organization {org} to {name}. slots: org: path.connectedOrganization-id name: requestBody.displayName - text: Set the state of connected organization {org} to {state}. slots: org: path.connectedOrganization-id state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/externalSponsors'].get update: x-apievangelist-phrasing: intent: List a connected organization's external sponsors effect: read questions: - Who are the external sponsors that approve requests for a connected organization? - Can I see the outside users sponsoring a connected organization's access requests? instructions: - text: List the external sponsors of connected organization {org}. slots: org: path.connectedOrganization-id - text: Show external sponsors matching {filter} for connected organization {org}. slots: filter: query.$filter org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/externalSponsors/{directoryObject-id}/$ref'].delete update: x-apievangelist-phrasing: intent: Remove one external sponsor by id effect: destructive questions: - How do I take a specific user or group off a connected organization's external sponsors by id? - Can I drop one external sponsor from a connected organization using its directory object id? instructions: - text: Remove external sponsor {sponsor} from connected organization {org}. slots: sponsor: path.directoryObject-id org: path.connectedOrganization-id - text: Take directory object {sponsor} off the external sponsor list of connected organization {org}. slots: sponsor: path.directoryObject-id org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/externalSponsors/$count'].get update: x-apievangelist-phrasing: intent: Count a connected organization's external sponsors effect: read questions: - How many external sponsors does a connected organization have? - Can I get just a count of external approvers for a connected organization? instructions: - text: Count the external sponsors of connected organization {org}. slots: org: path.connectedOrganization-id - text: Count external sponsors matching {filter} on connected organization {org}. slots: filter: query.$filter org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/externalSponsors/$ref'].get update: x-apievangelist-phrasing: intent: List external sponsor references effect: read questions: - How do I get only the reference links for a connected organization's external sponsors? - Can I list external sponsor ids without their full user or group objects? instructions: - text: List external sponsor references for connected organization {org}. slots: org: path.connectedOrganization-id - text: Show the first {top} external sponsor refs on connected organization {org}. slots: top: query.$top org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/externalSponsors/$ref'].post update: x-apievangelist-phrasing: intent: Add an external sponsor effect: write questions: - How do I add a user or group as an external sponsor of a connected organization? - Can external sponsors approve access requests for other users from their organization? instructions: - text: Add {user_ref} as an external sponsor of connected organization {org}. slots: user_ref: requestBody.@odata.id org: path.connectedOrganization-id - text: Make the user or group at {user_ref} an external sponsor for connected organization {org}. slots: user_ref: requestBody.@odata.id org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/externalSponsors/$ref'].delete update: x-apievangelist-phrasing: intent: Remove an external sponsor by reference URI effect: destructive questions: - How do I remove an external sponsor from a connected organization using its reference URI? - Can I delete an external sponsor link by passing the directory object's @id? instructions: - text: Remove the external sponsor at {delete_uri} from connected organization {org}. slots: delete_uri: query.@id org: path.connectedOrganization-id - text: Delete the external sponsor reference {delete_uri} on connected organization {org}. slots: delete_uri: query.@id org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/internalSponsors'].get update: x-apievangelist-phrasing: intent: List a connected organization's internal sponsors effect: read questions: - Which people in my own tenant sponsor a connected organization? - Can I see internal sponsors who approve requests for users from a connected organization? instructions: - text: List the internal sponsors of connected organization {org}. slots: org: path.connectedOrganization-id - text: Show internal sponsors matching {filter} for connected organization {org}. slots: filter: query.$filter org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/internalSponsors/{directoryObject-id}/$ref'].delete update: x-apievangelist-phrasing: intent: Remove one internal sponsor by id effect: destructive questions: - Which call removes one in-tenant sponsor from a connected organization when I know its object id? - Can I unassign a colleague as internal sponsor of a partner organization by their id? instructions: - text: Remove internal sponsor {sponsor} from connected organization {org}. slots: sponsor: path.directoryObject-id org: path.connectedOrganization-id - text: Take directory object {sponsor} off the internal sponsor list of connected organization {org}. slots: sponsor: path.directoryObject-id org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/internalSponsors/$count'].get update: x-apievangelist-phrasing: intent: Count a connected organization's internal sponsors effect: read questions: - How many internal sponsors does a connected organization have? - Can I get just a count of in-tenant approvers for a connected organization? instructions: - text: Count the internal sponsors of connected organization {org}. slots: org: path.connectedOrganization-id - text: Count internal sponsors matching {filter} on connected organization {org}. slots: filter: query.$filter org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/internalSponsors/$ref'].get update: x-apievangelist-phrasing: intent: List internal sponsor references effect: read questions: - Is there a way to fetch just the @odata.id links of a connected organization's internal sponsors? - Can I list internal sponsor ids without expanding each user or group? instructions: - text: List internal sponsor references for connected organization {org}. slots: org: path.connectedOrganization-id - text: Show the first {top} internal sponsor refs on connected organization {org}. slots: top: query.$top org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/internalSponsors/$ref'].post update: x-apievangelist-phrasing: intent: Add an internal sponsor effect: write questions: - How do I add someone from my tenant as an internal sponsor of a connected organization? - Can a group be an internal sponsor for a connected organization? instructions: - text: Add {user_ref} as an internal sponsor of connected organization {org}. slots: user_ref: requestBody.@odata.id org: path.connectedOrganization-id - text: Make the user or group at {user_ref} an internal sponsor for connected organization {org}. slots: user_ref: requestBody.@odata.id org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/{connectedOrganization-id}/internalSponsors/$ref'].delete update: x-apievangelist-phrasing: intent: Remove an internal sponsor by reference URI effect: destructive questions: - How can I unlink an in-tenant sponsor from a connected organization with an @id delete URI? - Can I pass an etag when unlinking an internal sponsor by its reference URI? instructions: - text: Remove the internal sponsor at {delete_uri} from connected organization {org}. slots: delete_uri: query.@id org: path.connectedOrganization-id - text: Delete the internal sponsor reference {delete_uri} on connected organization {org}. slots: delete_uri: query.@id org: path.connectedOrganization-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/connectedOrganizations/$count'].get update: x-apievangelist-phrasing: intent: Count connected organizations effect: read questions: - How many connected organizations are set up in my tenant? - Can I count connected organizations in a particular state? instructions: - text: Count my connected organizations. - text: Count connected organizations matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/controlConfigurations'].get update: x-apievangelist-phrasing: intent: List entitlement control configurations effect: read questions: - What control configurations are defined for entitlement management? - Can I see which entitlement management control configurations are enabled? instructions: - text: List the entitlement management control configurations. - text: Show control configurations matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/controlConfigurations'].post update: x-apievangelist-phrasing: intent: Create a control configuration effect: write questions: - How do I create a new control configuration in entitlement management? - Can I create a control configuration that starts out disabled? instructions: - text: Create a control configuration with enabled set to {enabled}. slots: enabled: requestBody.isEnabled - text: Add a new entitlement management control configuration. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/controlConfigurations/{controlConfiguration-id}'].get update: x-apievangelist-phrasing: intent: Get a control configuration effect: read questions: - Who created a given control configuration and is it currently enabled? - Where can I see when an entitlement control configuration was last modified? instructions: - text: Get control configuration {config}. slots: config: path.controlConfiguration-id - text: Show who last modified control configuration {config} and when. slots: config: path.controlConfiguration-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/controlConfigurations/{controlConfiguration-id}'].put update: x-apievangelist-phrasing: intent: Replace a control configuration effect: write questions: - How do I turn an existing entitlement control configuration on or off? - Can I replace the whole control configuration record in one call? instructions: - text: Set enabled to {enabled} on control configuration {config}. slots: enabled: requestBody.isEnabled config: path.controlConfiguration-id - text: Replace control configuration {config} with new settings. slots: config: path.controlConfiguration-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/controlConfigurations/{controlConfiguration-id}'].delete update: x-apievangelist-phrasing: intent: Delete a control configuration effect: destructive questions: - How do I delete a control configuration from entitlement management? - Can I remove a control configuration only if its etag still matches? instructions: - text: Delete control configuration {config}. slots: config: path.controlConfiguration-id - text: Remove control configuration {config} with etag {etag}. slots: config: path.controlConfiguration-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/controlConfigurations/$count'].get update: x-apievangelist-phrasing: intent: Count control configurations effect: read questions: - How many control configurations does entitlement management have? - Can I count only the enabled control configurations? instructions: - text: Count the entitlement control configurations. - text: Count control configurations matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments'].get update: x-apievangelist-phrasing: intent: List resource environments effect: read questions: - Which resource environments, like SharePoint Online sites, are registered for entitlement management? - Can I see which access package resource environment is the default one? instructions: - text: List all access package resource environments. - text: Show resource environments matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments'].post update: x-apievangelist-phrasing: intent: Register a resource environment effect: write questions: - How do I add a new resource environment for access package resources? - Can I record the origin system and origin id when registering a resource environment? instructions: - text: Create a resource environment named {name} in origin system {origin_system}. slots: name: requestBody.displayName origin_system: requestBody.originSystem - text: Register a resource environment with origin id {origin_id} and description {description}. slots: origin_id: requestBody.originId description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}'].get update: x-apievangelist-phrasing: intent: Get a resource environment effect: read questions: - What connection info and origin system does a given resource environment have? - Is a particular access package resource environment the default environment? instructions: - text: Get resource environment {env}. slots: env: path.accessPackageResourceEnvironment-id - text: Show the origin system and connection details of environment {env}. slots: env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}'].delete update: x-apievangelist-phrasing: intent: Delete a resource environment effect: destructive questions: - How do I remove a resource environment from entitlement management? - Can I delete an access package resource environment only when its etag matches? instructions: - text: Delete resource environment {env}. slots: env: path.accessPackageResourceEnvironment-id - text: Remove environment {env} with etag {etag}. slots: env: path.accessPackageResourceEnvironment-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource environment effect: write questions: - How do I rename or re-describe an access package resource environment? - Can I change the origin id stored on an existing resource environment? instructions: - text: Rename resource environment {env} to {name}. slots: env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Update the description of environment {env} to {description}. slots: env: path.accessPackageResourceEnvironment-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources'].get update: x-apievangelist-phrasing: intent: List resources in an environment effect: read questions: - Which access package resources live in a particular resource environment? - Can I filter an environment's resources by display name? instructions: - text: List the resources in environment {env}. slots: env: path.accessPackageResourceEnvironment-id - text: Show resources matching {filter} in resource environment {env}. slots: filter: query.$filter env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources'].post update: x-apievangelist-phrasing: intent: Add a resource to an environment effect: write questions: - How do I create an access package resource inside a resource environment? - Can I give a new environment resource an origin id from its source system? instructions: - text: Create a resource named {name} in environment {env}. slots: name: requestBody.displayName env: path.accessPackageResourceEnvironment-id - text: Add a resource with origin id {origin_id} from {origin_system} to environment {env}. slots: origin_id: requestBody.originId origin_system: requestBody.originSystem env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}'].get update: x-apievangelist-phrasing: intent: Get a resource in an environment effect: read questions: - What attributes does one resource in a resource environment have? - Where do I see when an environment's resource was created or last modified? instructions: - text: Get resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the attributes and timestamps of resource {resource} within environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}'].delete update: x-apievangelist-phrasing: intent: Remove a resource from an environment effect: destructive questions: - How do I delete a resource from a resource environment? - Can I remove an environment resource that no access package uses anymore? instructions: - text: Delete resource {resource} from environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Remove resource {resource} out of resource environment {env} with etag {etag}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource in an environment effect: write questions: - How do I rename a resource that lives in a resource environment? - Can I update an environment resource's description? instructions: - text: Rename resource {resource} in environment {env} to {name}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Change resource {resource}'s description in environment {env} to {description}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of an environment resource effect: read questions: - How do I read back the environment object linked from one of an environment's resources? - Can I expand from an environment resource to its hosting environment record? instructions: - text: Get the environment linked to resource {resource} under environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the hosting environment object for resource {resource} listed in {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a resource in an environment effect: write questions: - How do I refresh a resource that belongs to a resource environment? - Can I trigger a refresh on an environment resource so its details are up to date? instructions: - text: Refresh resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Run the refresh action on environment {env}'s resource {resource}. slots: env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles'].get update: x-apievangelist-phrasing: intent: List roles of an environment resource effect: read questions: - What roles, like Owner or Member, does a resource in a resource environment offer? - Can I filter roles on an environment resource by name? instructions: - text: List roles on resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show roles matching {filter} for environment {env}'s resource {resource}. slots: filter: query.$filter env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles'].post update: x-apievangelist-phrasing: intent: Add a role to an environment resource effect: write questions: - How do I create a role on a resource that lives in a resource environment? - Can I set a role type when adding a role to an environment resource? instructions: - text: Create a role named {name} on resource {resource} in environment {env}. slots: name: requestBody.displayName resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Add a role of type {role_type} to environment {env}'s resource {resource}. slots: role_type: requestBody.type env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role of an environment resource effect: read questions: - What are the details of one role on an environment resource? - Can I look up a role's origin id on a resource in a resource environment? instructions: - text: Get role {role} on resource {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show origin id and type of role {role} for environment {env}'s resource {resource}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role from an environment resource effect: destructive questions: - How do I delete a role from a resource in a resource environment? - Can I remove an unused role from an environment resource? instructions: - text: Delete role {role} from resource {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Remove role {role} off environment {env}'s resource {resource}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role of an environment resource effect: write questions: - How do I rename a role on a resource that lives in a resource environment? - Can I change a role's description on an environment resource? instructions: - text: Rename role {role} on resource {resource} in environment {env} to {name}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Set the description of role {role} for environment {env}'s resource {resource} to {description}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get a role's resource in an environment effect: read questions: - How do I navigate from a role back to the resource it belongs to inside a resource environment? - Can I read a role's parent resource details through the environment path? instructions: - text: Get the resource of role {role} on resource {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the parent resource for role {role} under environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink a role's resource in an environment effect: destructive questions: - How do I delete the resource navigation from a role in a resource environment? - Can I detach a role from its parent resource on the environment path? instructions: - text: Delete the resource link on role {role} of resource {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Remove the parent resource from role {role} under environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update a role's resource in an environment effect: write questions: - How do I edit the parent resource of a role through the resource environment path? - Can I rename a role's parent resource from inside a resource environment? instructions: - text: Rename the resource of role {role} on resource {resource} in environment {env} to {name}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Update the parent resource description of role {role} under environment {env} resource {resource} to {description}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a role's resource effect: read questions: - What environment hosts the parent resource of a role, starting from an environment resource? - Can I get the environment record for a role's resource on the environment path? instructions: - text: Look up which environment hosts the parent resource of role {role} on {resource} in {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the hosting environment for role {role}'s parent resource under environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a role's resource in an environment effect: write questions: - How do I refresh the parent resource of a role inside a resource environment? - Can I trigger a refresh on a role's resource from the environment path? instructions: - text: Refresh the resource of role {role} on resource {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Run a refresh on role {role}'s parent resource under environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a role's resource in an environment effect: read questions: - Which scopes does a role's parent resource have inside a resource environment? - Can I list the sites or folders a role's resource exposes as scopes from the environment path? instructions: - text: List scopes on role {role}'s resource for resource {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show scopes matching {filter} on role {role}'s parent resource under environment {env} resource {resource}. slots: filter: query.$filter role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a role's resource in an environment effect: write questions: - How do I create a scope on the parent resource of a role in a resource environment? - Can I mark a new scope on a role's resource as the root scope via the environment path? instructions: - text: Create a scope named {name} on role {role}'s resource for resource {resource} in environment {env}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Add a scope with origin id {origin_id} to role {role}'s parent resource under environment {env} resource {resource}. slots: origin_id: requestBody.originId role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope of a role's resource in an environment effect: read questions: - What are the details of one scope on a role's parent resource in a resource environment? - Can I check whether a scope under a role's resource is a root scope from the environment path? instructions: - text: Get scope {scope} on role {role}'s resource for resource {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show scope {scope} details on role {role}'s parent resource under environment {env} resource {resource}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope of a role's resource in an environment effect: destructive questions: - How do I delete a scope from a role's parent resource in a resource environment? - Can I remove a scope under a role's resource while on the environment path? instructions: - text: Delete scope {scope} from role {role}'s resource for resource {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Remove scope {scope} of role {role}'s parent resource under environment {env} resource {resource}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope of a role's resource in an environment effect: write questions: - How do I rename a scope on a role's parent resource in a resource environment? - Can I change a scope's description under a role's resource from the environment path? instructions: - text: Rename scope {scope} on role {role}'s resource for resource {resource} in environment {env} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Set scope {scope}'s description to {description} on role {role}'s parent resource under {env} resource {resource}. slots: scope: path.accessPackageResourceScope-id description: requestBody.description role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get a scope's resource under a role, in an environment effect: read questions: - Which resource does a scope belong to when I reach it through a role inside a resource environment? - Can I walk from a scope on a role's resource to that scope's own resource in the environment tree? instructions: - text: Get the resource of scope {scope} under role {role}, resource {resource}, environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the scope-level resource that scope {scope} points to beneath role {role} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink a scope's resource under a role, in an environment effect: destructive questions: - How do I delete the resource navigation from a scope that sits under a role in a resource environment? - Can I detach a scope beneath a role's resource from its own resource in the environment tree? instructions: - text: Delete the resource link on scope {scope} under role {role}, resource {resource}, environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Detach scope {scope} from its scope-level resource beneath role {role} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update a scope's resource under a role, in an environment effect: write questions: - How do I edit the resource a scope points to when that scope sits under a role in an environment? - Can I rename the scope-level resource beneath a role in the environment tree? instructions: - text: Rename the resource of scope {scope} under role {role}, resource {resource}, environment {env} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Update the scope-level resource description for scope {scope} beneath role {role} of {resource} in {env} to {description}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a scope's resource under a role effect: read questions: - Which environment hosts the resource of a scope that sits under a role in the environment tree? - Can I read the environment record for a scope-level resource beneath a role? instructions: - text: Look up the hosting environment of scope {scope}'s own resource below role {role}, resource {resource}, {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show where the scope-level resource of scope {scope} beneath role {role} of {resource} in {env} is hosted. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a scope's resource under a role, in an environment effect: write questions: - How do I refresh the resource of a scope that sits under a role in a resource environment? - Can I trigger a refresh of a scope-level resource beneath a role in the environment tree? instructions: - text: Refresh the resource of scope {scope} under role {role}, resource {resource}, environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Run a refresh on the scope-level resource of scope {scope} beneath role {role} of {resource} in {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a scope's resource under a role effect: read questions: - Which upload sessions exist for a scope-level resource beneath a role in a resource environment? - Can I list custom data uploads for the resource of a scope under a role in the environment tree? instructions: - text: List upload sessions on scope {scope}'s resource under role {role}, resource {resource}, environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the first {top} uploads for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: top: query.$top scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a scope's resource under a role effect: write questions: - How do I create an upload session on a scope-level resource beneath a role in an environment? - Can I link a new upload session under a role's scope resource to an access review reference? instructions: - text: Create an upload session on scope {scope}'s resource under role {role}, resource {resource}, environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Open an upload for reference {reference} on the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: reference: requestBody.referenceId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a scope's resource under a role effect: read questions: - What is the status of an upload session on a scope-level resource beneath a role in an environment? - Can I see file stats for one upload session under a role's scope resource in the environment tree? instructions: - text: Get session {session} on scope {scope}'s resource under role {role}, resource {resource}, environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show status of session {session} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a scope's resource under a role effect: destructive questions: - What's the way to remove an active upload session from a scope-level resource beneath a role in an environment? - Can I discard the upload session of a role's scope resource in the environment tree and restart? instructions: - text: Delete session {session} on scope {scope}'s resource under role {role}, resource {resource}, environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Discard session {session} from the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a scope's resource under a role effect: write questions: - How do I mark an upload session complete on a scope-level resource beneath a role in an environment? - Can I update the reference of an upload session under a role's scope resource in the environment tree? instructions: - text: Set upload done {upload_done} on session {session}, scope {scope}, role {role}, resource {resource}, environment {env}. slots: upload_done: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Change session {session} reference to {reference} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: session: path.customDataProvidedResourceUploadSession-id reference: requestBody.referenceId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files of a scope resource session under a role effect: read questions: - What files are in an upload session on a scope-level resource beneath a role in an environment? - Can I list uploaded files for a role's scope resource session in the environment tree? instructions: - text: List files in session {session} on scope {scope}'s resource under role {role}, resource {resource}, environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show uploaded files of {session} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file of a scope resource session under a role effect: read questions: - What details does one file have in a session on a scope-level resource beneath a role in an environment? - Can I get one uploaded file record for a role's scope resource in the environment tree? instructions: - text: Get file {file} in session {session}, scope {scope}, role {role}, resource {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show metadata of {file} in {session} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file of a scope resource session under a role effect: read questions: - How do I download file bytes from a session on a scope-level resource beneath a role in an environment? - Can I get raw uploaded content for a role's scope resource in the environment tree? instructions: - text: Download file {file} content from session {session}, scope {scope}, role {role}, resource {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Fetch raw media of {file} in {session} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file of a scope resource session under a role effect: write questions: - How do I overwrite a file in a session on a scope-level resource beneath a role in an environment? - Can I re-upload bytes for an existing file on a role's scope resource in the environment tree? instructions: - text: Replace file {file} content in session {session}, scope {scope}, role {role}, resource {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Overwrite media of {file} in {session} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear a file of a scope resource session under a role effect: destructive questions: - How do I delete file content from a session on a scope-level resource beneath a role in an environment? - Can I wipe the bytes of a wrong upload on a role's scope resource in the environment tree? instructions: - text: Delete file {file} content in session {session}, scope {scope}, role {role}, resource {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Wipe stored bytes of {file} in {session} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files of a scope resource session under a role effect: read questions: - How many files are in a session on a scope-level resource beneath a role in an environment? - Is there a quick tally of how many files a role's scope resource session holds in the environment tree? instructions: - text: Count files in session {session}, scope {scope}, role {role}, resource {resource}, environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Tell me the file count of {session} for the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a scope's resource under a role effect: write questions: - How do I upload a custom data file for a scope-level resource beneath a role in an environment? - Can I add more files to an open session on a role's scope resource in the environment tree? instructions: - text: Upload a file into session {session}, scope {scope}, role {role}, resource {resource}, environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Send a custom data file via {session} to the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a scope's resource under a role effect: read questions: - How many upload sessions exist on a scope-level resource beneath a role in an environment? - Can I count upload sessions for a role's scope resource in the environment tree by status? instructions: - text: Count upload sessions on scope {scope}'s resource under role {role}, resource {resource}, environment {env}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count sessions matching {filter} on the scope-level resource of {scope} beneath role {role} of {resource} in {env}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a role's resource in an environment effect: read questions: - How many scopes does a role's parent resource have inside a resource environment? - Can I count root scopes on a role's resource from the environment path? instructions: - text: Count scopes on role {role}'s resource for resource {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count scopes matching {filter} on role {role}'s parent resource under environment {env} resource {resource}. slots: filter: query.$filter role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a role's resource in an environment effect: read questions: - Which upload sessions have been opened on a role's parent resource inside a resource environment? - Can I list custom data upload sessions for a role's resource from the environment path? instructions: - text: List upload sessions for role {role}'s resource on {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the first {top} upload sessions of role {role}'s parent resource, environment {env} resource {resource}. slots: top: query.$top role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open a role resource upload session (environment) effect: write questions: - How do I start an upload session on a role's parent resource inside a resource environment? - Can I tie a new upload session for a role's resource to an access review on the environment path? instructions: - text: Create an upload session for role {role}'s resource on {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Open an upload session with reference {reference} on role {role}'s parent resource, environment {env} resource {resource}. slots: reference: requestBody.referenceId role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a role's resource in an environment effect: read questions: - What is the status of one upload session on a role's parent resource in a resource environment? - Can I check whether uploading is done for a role resource session on the environment path? instructions: - text: Get upload session {session} for role {role}'s resource on {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show progress of session {session} on role {role}'s parent resource, environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role resource upload session (environment) effect: destructive questions: - How do I delete an upload session on a role's parent resource in a resource environment? - Can I throw away a role resource's upload session on the environment path to start again? instructions: - text: Delete upload session {session} for role {role}'s resource on {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Discard session {session} of role {role}'s parent resource, environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update a role resource upload session (environment) effect: write questions: - How do I mark an upload session done on a role's parent resource in a resource environment? - Can I change the reference on a role resource's upload session from the environment path? instructions: - text: Set upload done to {upload_done} on session {session} for role {role}'s resource on {resource} in environment {env}. slots: upload_done: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Update session {session} reference to {reference} on role {role}'s parent resource, environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id reference: requestBody.referenceId role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files of a role resource's session in an environment effect: read questions: - Which files were uploaded to a session on a role's parent resource in a resource environment? - Can I list files of a role resource's upload session from the environment path? instructions: - text: List files in session {session} for role {role}'s resource on {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the uploaded files of session {session}, role {role}'s parent resource, environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file of a role resource's session in an environment effect: read questions: - What metadata is kept for one file in a role resource's upload session in an environment? - Can I read a single file record in a role resource session on the environment path? instructions: - text: Get file {file} in session {session} for role {role}'s resource on {resource} in environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show file {file} of session {session}, role {role}'s parent resource, environment {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a role resource session file (environment) effect: read questions: - How do I download a file's bytes from a role resource upload session in a resource environment? - Can I fetch the raw content of an uploaded file for a role's parent resource on the environment path? instructions: - text: Download file {file} content in session {session} for role {role}'s resource on {resource} in environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Fetch raw media of {file}, session {session}, role {role}'s parent resource, environment {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a role resource session file (environment) effect: write questions: - How do I overwrite an uploaded file on a role's parent resource in a resource environment? - Can I replace file bytes in a role resource session from the environment path? instructions: - text: Replace file {file} content in session {session} for role {role}'s resource on {resource} in environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Overwrite media of {file}, session {session}, role {role}'s parent resource, environment {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear a file of a role resource's session in an environment effect: destructive questions: - How do I delete a file's content from a role resource upload session in a resource environment? - Can I wipe the bytes of a bad file for a role's parent resource on the environment path? instructions: - text: Delete file {file} content in session {session} for role {role}'s resource on {resource} in environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Wipe stored bytes of {file}, session {session}, role {role}'s parent resource, environment {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files of a role resource's session in an environment effect: read questions: - How many files are in an upload session on a role's parent resource in a resource environment? - Can I count uploaded files for a role resource session on the environment path? instructions: - text: Count files in session {session} for role {role}'s resource on {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Tell me the number of files in {session} for role {role}'s parent resource, environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a role's resource in an environment effect: write questions: - How do I upload a custom data file for a role's parent resource in a resource environment? - Can I add another file to a role resource upload session on the environment path? instructions: - text: Upload a file into session {session} for role {role}'s resource on {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Send a custom data file via {session} to role {role}'s parent resource, environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a role's resource in an environment effect: read questions: - How many upload sessions exist on a role's parent resource in a resource environment? - Can I count role resource upload sessions from the environment path by status? instructions: - text: Count upload sessions for role {role}'s resource on {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count sessions matching {filter} on role {role}'s parent resource, environment {env} resource {resource}. slots: filter: query.$filter role: path.accessPackageResourceRole-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of an environment resource effect: read questions: - How many roles does a resource in a resource environment have? - Can I count an environment resource's roles that match a filter? instructions: - text: Count roles on resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count roles matching {filter} for environment {env}'s resource {resource}. slots: filter: query.$filter env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of an environment resource effect: read questions: - Which scopes, such as sites or folders, does a resource in a resource environment expose? - Can I filter an environment resource's scopes to only the root scope? instructions: - text: List scopes on resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show scopes matching {filter} for environment {env}'s resource {resource}. slots: filter: query.$filter env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to an environment resource effect: write questions: - How do I create a scope on a resource that lives in a resource environment? - Can I record where a new environment resource scope came from in its origin system? instructions: - text: Create a scope named {name} on resource {resource} in environment {env}. slots: name: requestBody.displayName resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Add a scope with origin id {origin_id} to environment {env}'s resource {resource}. slots: origin_id: requestBody.originId env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope of an environment resource effect: read questions: - What are the details of one scope on a resource in a resource environment? - Is a particular scope on an environment resource the root scope? instructions: - text: Get scope {scope} on resource {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show origin id and root flag of scope {scope} for environment {env}'s resource {resource}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope from an environment resource effect: destructive questions: - How do I delete a scope from a resource in a resource environment? - Can I remove an obsolete scope from an environment resource? instructions: - text: Delete scope {scope} from resource {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Remove scope {scope} off environment {env}'s resource {resource}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope of an environment resource effect: write questions: - How do I rename a scope on a resource that lives in a resource environment? - Can I change the wording that describes one scope on an environment resource? instructions: - text: Rename scope {scope} on resource {resource} in environment {env} to {name}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Set scope {scope}'s description for environment {env}'s resource {resource} to {description}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource behind an environment scope effect: read questions: - How do I read the resource object that a scope on an environment resource points back to? - Can I navigate from a scope to its resource while browsing a resource environment? instructions: - text: Fetch the resource record that scope {scope} references, under {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show which resource scope {scope} links to, starting at environment {env} resource {resource}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource from an environment scope effect: destructive questions: - How do I delete the resource navigation from a scope on an environment resource? - Can I detach a scope in a resource environment from the resource it references? instructions: - text: Delete the resource link on scope {scope} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Detach scope {scope} from its referenced resource, starting at environment {env} resource {resource}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource behind an environment scope effect: write questions: - How do I edit the resource a scope references while working in a resource environment? - Can I rename the resource behind a scope from the environment path? instructions: - text: Rename the resource behind scope {scope} of {resource} in environment {env} to {name}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Update the description of the resource scope {scope} links to, at environment {env} resource {resource}, to {description}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of an environment scope's resource effect: read questions: - Which environment hosts the resource behind a scope, reached from a resource environment? - Can I read the environment record of a scope's referenced resource on the environment path? instructions: - text: Look up the hosting environment for the resource scope {scope} references, under {resource} in {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the hosting environment record for scope {scope}'s referenced resource at {env} resource {resource}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource behind an environment scope effect: write questions: - How do I refresh the resource behind a scope while browsing a resource environment? - Can I trigger a refresh of a scope's referenced resource from the environment path? instructions: - text: Refresh the resource behind scope {scope} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Run the refresh action on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of an environment scope's resource effect: read questions: - What roles does the resource behind a scope offer, reached from a resource environment? - Can I filter the roles of a scope's referenced resource on the environment path? instructions: - text: List roles of the resource behind scope {scope} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show roles matching {filter} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to an environment scope's resource effect: write questions: - How do I create a role on the resource behind a scope within a resource environment? - Can I set a role type on a new role for a scope's referenced resource in an environment? instructions: - text: Create a role named {name} on the resource behind scope {scope} of {resource} in environment {env}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Add a role of type {role_type} to scope {scope}'s referenced resource at environment {env} resource {resource}. slots: role_type: requestBody.type scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role of an environment scope's resource effect: read questions: - What are the details of a role on the resource behind a scope in a resource environment? - Can I read a role's origin id on a scope's referenced resource via the environment path? instructions: - text: Read role {role} defined on the resource that scope {scope} references, under {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show role {role} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role of an environment scope's resource effect: destructive questions: - How do I delete a role from the resource behind a scope in a resource environment? - Can I remove a role on a scope's referenced resource via the environment path? instructions: - text: Delete role {role} from the resource behind scope {scope} of {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Remove role {role} off scope {scope}'s referenced resource at environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role of an environment scope's resource effect: write questions: - How do I rename a role on the resource behind a scope in a resource environment? - Can I update a role's description on a scope's referenced resource via the environment path? instructions: - text: Give role {role}, on the resource scope {scope} references in environment {env} resource {resource}, the name {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id name: requestBody.displayName - text: Set role {role}'s description to {description} on scope {scope}'s referenced resource at {env} resource {resource}. slots: role: path.accessPackageResourceRole-id description: requestBody.description scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get a role-level resource reached from an environment scope effect: read questions: - Which resource does a role belong to when I reach that role from a scope in a resource environment? - Can I go from scope to role to the role-level resource in the environment tree? instructions: - text: Get the role-level resource of role {role}, reached from scope {scope} of {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the resource that role {role} belongs to via scope {scope}, starting at environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink a role-level resource via an environment scope effect: destructive questions: - How do I delete the resource link on a role I reached through a scope in a resource environment? - Can I detach a role-level resource from a role found via a scope in the environment tree? instructions: - text: Delete the role-level resource link of role {role}, reached from scope {scope} of {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Detach role {role} from its resource via scope {scope}, starting at environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update a role-level resource via an environment scope effect: write questions: - How do I edit the resource a role belongs to after reaching that role via a scope in an environment? - Can I rename a role-level resource found through a scope in the environment tree? instructions: - text: Rename the role-level resource of role {role}, reached from scope {scope} of {resource} in {env}, to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id name: requestBody.displayName - text: Update the description of role {role}'s own resource via scope {scope} at environment {env} resource {resource} to {description}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a role-level resource via a scope effect: read questions: - What environment hosts a role-level resource that I reached via a scope in a resource environment? - Can I read the environment record for a role's resource found through a scope in the environment tree? instructions: - text: Get the environment of role {role}'s resource, reached from scope {scope} of {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the hosting environment of the role-level resource for {role} via scope {scope} at {env} resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a role-level resource via an environment scope effect: write questions: - How do I refresh a role-level resource that I reached via a scope in a resource environment? - Can I trigger a refresh on a role's resource found through a scope in the environment tree? instructions: - text: Refresh the role-level resource of role {role}, reached from scope {scope} of {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Run a refresh on role {role}'s own resource via scope {scope} at environment {env} resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a role-level resource via a scope effect: read questions: - Which upload sessions exist on a role-level resource reached via a scope in a resource environment? - Can I list custom data uploads for a role's resource found through a scope in the environment tree? instructions: - text: List upload sessions on role {role}'s role-level resource, from scope {scope} of {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the first {top} upload sessions for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: top: query.$top role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a role-level resource via a scope effect: write questions: - How do I start an upload session on a role-level resource reached via a scope in an environment? - Can I link an upload session on a role's resource found through a scope to an access review? instructions: - text: Create an upload session on role {role}'s role-level resource, from scope {scope} of {resource} in environment {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Open an upload for reference {reference} on role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: reference: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a role-level resource via a scope effect: read questions: - What is the status of an upload session on a role-level resource reached via a scope in an environment? - Can I check upload progress for a role's resource found through a scope in the environment tree? instructions: - text: Get session {session} on role {role}'s role-level resource, from scope {scope} of {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show progress of {session} for role {role}'s own resource via scope {scope} at environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role-level resource's upload session via scope effect: destructive questions: - What's the way to discard an upload session on a role-level resource reached via a scope in an environment? - Can I delete a role resource's session found through a scope in the environment tree and begin again? instructions: - text: Delete session {session} on role {role}'s role-level resource, from scope {scope} of {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Discard {session} for role {role}'s own resource via scope {scope} at environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update a role-level resource's upload session via scope effect: write questions: - How do I mark uploading done on a role-level resource session reached via a scope in an environment? - Can I change the reference on a role resource's session found through a scope in the environment tree? instructions: - text: Set upload done {upload_done} on {session}, role {role}'s role-level resource, scope {scope}, {resource}, environment {env}. slots: upload_done: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Change {session} reference to {reference} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id reference: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files of a role-level resource session via a scope effect: read questions: - What files are in a session on a role-level resource reached via a scope in a resource environment? - Can I list uploads inside a role resource session found through a scope in the environment tree? instructions: - text: List files in {session} on role {role}'s role-level resource, from scope {scope} of {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show uploaded files of {session} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file of a role-level resource session via a scope effect: read questions: - What details does one file have in a session on a role-level resource reached via a scope? - Can I read a single uploaded file for a role's resource found through a scope in the environment tree? instructions: - text: Get file {file} in {session}, role {role}'s role-level resource, scope {scope}, {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show metadata of {file} in {session} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file of a role-level resource session via a scope effect: read questions: - How do I download file bytes from a session on a role-level resource reached via a scope? - Is it possible to pull the actual uploaded bytes for a role's own resource that I found via a scope? instructions: - text: Download {file} content from {session}, role {role}'s role-level resource, scope {scope}, {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Fetch raw media of {file} in {session} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file of a role-level resource session via a scope effect: write questions: - How do I overwrite a file in a session on a role-level resource reached via a scope? - Can I re-send bytes for a file uploaded to a role's resource found through a scope in the environment tree? instructions: - text: Replace {file} content in {session}, role {role}'s role-level resource, scope {scope}, {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Overwrite media of {file} in {session} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear a file of a role-level resource session via a scope effect: destructive questions: - How do I delete a file's content from a session on a role-level resource reached via a scope? - Can I wipe a bad upload for a role's resource found through a scope in the environment tree? instructions: - text: Delete {file} content in {session}, role {role}'s role-level resource, scope {scope}, {resource}, environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Wipe stored bytes of {file} in {session} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files of a role-level resource session via a scope effect: read questions: - How many files are in a session on a role-level resource reached via a scope in an environment? - Is there a quick file tally for a role resource session found through a scope in the environment tree? instructions: - text: Count files in {session}, role {role}'s role-level resource, scope {scope}, {resource}, environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Tell me the file count of {session} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for a role-level resource via a scope effect: write questions: - How do I upload a custom data file for a role-level resource reached via a scope in an environment? - Can I push more files into a role resource session found through a scope in the environment tree? instructions: - text: Upload a file into {session}, role {role}'s role-level resource, scope {scope}, {resource}, environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Send a custom data file via {session} to role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a role-level resource via a scope effect: read questions: - How many upload sessions exist on a role-level resource reached via a scope in an environment? - Can I count sessions by status for a role's resource found through a scope in the environment tree? instructions: - text: Tell me how many upload sessions role {role}'s role-level resource has, via scope {scope} of {resource} in {env}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count sessions matching {filter} for role {role}'s own resource via scope {scope} at {env} resource {resource}. slots: filter: query.$filter role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of an environment scope's resource effect: read questions: - How many roles does the resource behind a scope have, reached from a resource environment? - Can I count roles on a scope's referenced resource via the environment path by name? instructions: - text: Count roles of the resource behind scope {scope} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count roles matching {filter} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of an environment scope's resource effect: read questions: - Which upload sessions exist for the resource behind a scope, reached from a resource environment? - Can I list custom data uploads for a scope's referenced resource on the environment path? instructions: - text: List upload sessions of the resource behind scope {scope} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the first {top} sessions on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: top: query.$top scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on an environment scope's resource effect: write questions: - How do I start an upload session on the resource behind a scope within a resource environment? - Does a new upload session on a scope's referenced resource accept an access review reference id? instructions: - text: Create an upload session on the resource behind scope {scope} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Open an upload for reference {reference} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: reference: requestBody.referenceId scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of an environment scope's resource effect: read questions: - What is the status of one upload session on the resource behind a scope in a resource environment? - Can I see upload stats for a scope's referenced resource session on the environment path? instructions: - text: Read upload session {session} opened on the resource that scope {scope} references, under {resource} in {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show progress of {session} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of an environment scope's resource effect: destructive questions: - What's the way to remove an upload session on the resource behind a scope in a resource environment? - Can I discard a scope resource's session on the environment path and start fresh? instructions: - text: Delete session {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Discard {session} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of an environment scope's resource effect: write questions: - How do I mark an upload session done on the resource behind a scope in a resource environment? - Can I update the reference on a scope resource's session via the environment path? instructions: - text: Set upload done {upload_done} on session {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: upload_done: requestBody.isUploadDone session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Change {session} reference to {reference} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id reference: requestBody.referenceId scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files of an environment scope resource's session effect: read questions: - What files were uploaded to a session on the resource behind a scope in a resource environment? - Can I list files of a scope resource's session on the environment path? instructions: - text: List files in {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show uploaded files of {session} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file of an environment scope resource's session effect: read questions: - What details are stored for one file in a scope resource's session in a resource environment? - Can I look up one uploaded file for a scope's referenced resource on the environment path? instructions: - text: Read uploaded file {file} from {session} on the resource that scope {scope} references, under {resource} in {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show metadata of {file} in {session} on scope {scope}'s referenced resource at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file of an environment scope resource's session effect: read questions: - How do I download the bytes of a file uploaded for the resource behind a scope in an environment? - Can I fetch raw file content from a scope resource session on the environment path? instructions: - text: Download {file} content from {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Fetch raw media of {file} in {session} on scope {scope}'s referenced resource at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file of an environment scope resource's session effect: write questions: - How do I overwrite a file uploaded for the resource behind a scope in a resource environment? - Can I replace an uploaded file's bytes on a scope's referenced resource via the environment path? instructions: - text: Replace {file} content in {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Overwrite media of {file} in {session} on scope {scope}'s referenced resource at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear a file of an environment scope resource's session effect: destructive questions: - How do I delete the content of a file uploaded for the resource behind a scope in an environment? - Can I wipe a wrong file's bytes on a scope's referenced resource via the environment path? instructions: - text: Delete {file} content in {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Wipe stored bytes of {file} in {session} on scope {scope}'s referenced resource at {env} resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files of an environment scope resource's session effect: read questions: - How many files are in a session on the resource behind a scope in a resource environment? - Is there a file count for a scope resource's session on the environment path? instructions: - text: Count files in {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Tell me the file count of {session} on scope {scope}'s referenced resource at {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file for an environment scope's resource effect: write questions: - How do I upload a custom data file for the resource behind a scope in a resource environment? - Can I add another file to a scope resource's session on the environment path? instructions: - text: Upload a file into {session} of the resource behind scope {scope} of {resource} in environment {env}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Send a custom data file via {session} to scope {scope}'s referenced resource at environment {env} resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of an environment scope's resource effect: read questions: - How many upload sessions exist on the resource behind a scope in a resource environment? - Can I count a scope resource's upload sessions by status on the environment path? instructions: - text: Count upload sessions of the resource behind scope {scope} of {resource} in environment {env}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count sessions matching {filter} on scope {scope}'s referenced resource at environment {env} resource {resource}. slots: filter: query.$filter scope: path.accessPackageResourceScope-id env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of an environment resource effect: read questions: - How many scopes does a resource in a resource environment have? - Can I count an environment resource's scopes that match a filter? instructions: - text: Count scopes on resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Count scopes matching {filter} for environment {env}'s resource {resource}. slots: filter: query.$filter env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of an environment resource effect: read questions: - Which custom data upload sessions have been opened for a resource in a resource environment? - Can I see only the first few upload sessions for an environment resource? instructions: - text: List upload sessions on resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show the first {top} upload sessions for environment {env}'s resource {resource}. slots: top: query.$top env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on an environment resource effect: write questions: - How do I start a custom data upload session directly on a resource in a resource environment? - Can I link an environment resource's new upload session to an access review instance? instructions: - text: Create an upload session on resource {resource} in environment {env}. slots: resource: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Open an upload session for reference {reference} on environment {env}'s resource {resource}. slots: reference: requestBody.referenceId env: path.accessPackageResourceEnvironment-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get a BYOD upload session for an environment resource effect: read questions: - What is the status of one bring-your-own-data upload session on a resource in a resource environment? - Can I check whether a BYOD upload on an environment's resource has finished? instructions: - text: Show details of upload session {sess} for resource {res} in environment {env}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Check whether upload session {sess} for resource {res} in environment {env} is done. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete a BYOD upload session for an environment resource effect: destructive questions: - Can I remove an abandoned upload session from a resource in a resource environment? - What happens if I delete a BYOD upload session tied to an environment's resource? instructions: - text: Delete upload session {sess} from resource {res} in environment {env}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Remove the stale BYOD upload session {sess} on environment {env} resource {res}. slots: sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update a BYOD upload session for an environment resource effect: write questions: - How do I mark a BYOD upload session on an environment's resource as finished? - Can I change the reference ID of an upload session attached to a resource in a resource environment? instructions: - text: Mark upload session {sess} for resource {res} in environment {env} as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id done: requestBody.isUploadDone - text: Set the reference {ref} on upload session {sess} for resource {res} in environment {env}. slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an environment resource's upload session effect: read questions: - Which files were uploaded in a BYOD session for a resource in a resource environment? - Can I sort or filter the files sent during an environment resource's upload session? instructions: - text: List files uploaded in session {sess} for resource {res} in environment {env}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Show every file sent through upload session {sess} on environment {env} resource {res}. slots: sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file from an environment resource's upload session effect: read questions: - Where do I see the metadata of a single file uploaded for a resource in a resource environment? - Can I look up one specific uploaded file in an environment resource's BYOD session? instructions: - text: Show metadata for uploaded file {file} in session {sess} for resource {res} in environment {env}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Look up file {file} from upload session {sess} on environment {env} resource {res}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file's content from an environment upload session effect: read questions: - How can I download the raw data of a file uploaded for a resource in a resource environment? - Is the original file content still retrievable from an environment resource's upload session? instructions: - text: Download the raw bytes of file {file} in session {sess} for resource {res} in environment {env}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Fetch the stored data of uploaded file {file} (session {sess}, environment {env}, resource {res}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file's content in an environment upload session effect: write questions: - Can I overwrite the content of a file already uploaded for a resource in a resource environment? - How do I re-upload corrected data into an existing file of an environment resource's session? instructions: - text: Overwrite file {file} with new content in session {sess} for resource {res} in environment {env}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Put corrected data into file {file} of upload session {sess} on environment {env} resource {res}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete a file's content in an environment upload session effect: destructive questions: - Can I erase the data of one uploaded file on a resource in a resource environment? - What removes the stored bytes of a BYOD file for an environment's resource? instructions: - text: Erase the stored content of file {file} in session {sess} for resource {res} in environment {env}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Clear the data held in uploaded file {file} (session {sess}, environment {env}, resource {res}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an environment resource's upload session effect: read questions: - How many files have been uploaded in a BYOD session for a resource in a resource environment? - Is there a quick file total for an environment resource's upload session? instructions: - text: Count the files uploaded to session {sess} for resource {res} in environment {env}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Tell me the number of files in upload session {sess} on environment {env} resource {res}. slots: sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file to an environment resource's session effect: write questions: - How do I push an access data file into a BYOD upload session for a resource in a resource environment? - Can I add another external access data file to an environment resource's open upload session? instructions: - text: Upload a data file into session {sess} for resource {res} in environment {env}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Send a new access data file through upload session {sess} on environment {env} resource {res}. slots: sess: path.customDataProvidedResourceUploadSession-id env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/{accessPackageResource-id}/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions for an environment resource effect: read questions: - How many BYOD upload sessions exist for a resource in a resource environment? - Is there a total of upload sessions started against an environment's resource? instructions: - text: Count how many upload sessions resource {res} in environment {env} has. slots: res: path.accessPackageResource-id env: path.accessPackageResourceEnvironment-id - text: Give me the number of BYOD upload sessions on environment {env} resource {res}. slots: env: path.accessPackageResourceEnvironment-id res: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/{accessPackageResourceEnvironment-id}/resources/$count'].get update: x-apievangelist-phrasing: intent: Count resources in a resource environment effect: read questions: - How many access package resources live in a given resource environment? - Can I get a resource total for one entitlement management resource environment? instructions: - text: Count the resources in resource environment {env}. slots: env: path.accessPackageResourceEnvironment-id - text: Tell me how many access package resources environment {env} holds. slots: env: path.accessPackageResourceEnvironment-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceEnvironments/$count'].get update: x-apievangelist-phrasing: intent: Count resource environments effect: read questions: - How many resource environments does entitlement management know about? - Is there a quick total of all access package resource environments in my tenant? instructions: - text: Count all resource environments in entitlement management. - text: Give me the number of access package resource environments. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests'].get update: x-apievangelist-phrasing: intent: List access package resource requests effect: read questions: - Which requests to add or remove catalog resources have been made in entitlement management? - Can I filter resource requests by state or request type in Microsoft Entra entitlement management? instructions: - text: List all access package resource requests. - text: Show resource requests filtered by {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests'].post update: x-apievangelist-phrasing: intent: Request adding or removing a catalog resource effect: write questions: - How do I add a group or app to an access package catalog? - Can I request removal of a resource from a catalog through entitlement management? instructions: - text: Submit a resource request of type {rtype} for resource {resource} in catalog {catalog}. slots: rtype: requestBody.requestType resource: requestBody.resource catalog: requestBody.catalog - text: Create a request to add resource {resource} to access package catalog {catalog}. slots: resource: requestBody.resource catalog: requestBody.catalog method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}'].get update: x-apievangelist-phrasing: intent: Get an access package resource request effect: read questions: - What is the current state of a specific catalog resource request? - Can I see which resource and catalog a single resource request targets? instructions: - text: Show resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Check the state of access package resource request {req}. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}'].delete update: x-apievangelist-phrasing: intent: Delete an access package resource request effect: destructive questions: - Can I delete a catalog resource request record I no longer need? - Is deleting a catalog resource request record permanent? instructions: - text: Delete resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Remove access package resource request {req} permanently. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}'].patch update: x-apievangelist-phrasing: intent: Update an access package resource request effect: write questions: - Can I change the request type or state of an existing catalog resource request? - How do I edit a resource request after it was submitted? instructions: - text: Update resource request {req} to state {state}. slots: req: path.accessPackageResourceRequest-id state: requestBody.state - text: Change the request type of resource request {req} to {rtype}. slots: req: path.accessPackageResourceRequest-id rtype: requestBody.requestType method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog'].get update: x-apievangelist-phrasing: intent: Get the catalog of a resource request effect: read questions: - Which access package catalog does a resource request point at? - Can I read the name and visibility of the catalog behind a resource request? instructions: - text: Show the catalog targeted by resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Get catalog details for resource request {req}. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog'].delete update: x-apievangelist-phrasing: intent: Delete the catalog linked to a resource request effect: destructive questions: - Can I delete the catalog that a resource request is attached to? - What does removing the catalog navigation link from a resource request do? instructions: - text: Delete the catalog linked to resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Remove the catalog reference from resource request {req}. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog'].patch update: x-apievangelist-phrasing: intent: Update the catalog of a resource request effect: write questions: - How do I rename the access package catalog behind a resource request? - Can I make the catalog on a resource request visible to external users? instructions: - text: Rename the catalog of resource request {req} to {name}. slots: req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set external visibility {visible} on the catalog of resource request {req}. slots: visible: requestBody.isExternallyVisible req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/accessPackages'].get update: x-apievangelist-phrasing: intent: List access packages in a request's catalog effect: read questions: - Which access packages sit in the catalog a resource request targets? - Can I page through the access packages of a resource request's catalog? instructions: - text: List access packages in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show the access packages offered by the catalog behind request {req}. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/accessPackages/{accessPackage-id}'].get update: x-apievangelist-phrasing: intent: Get an access package in a request's catalog effect: read questions: - Where do I read one access package from the catalog of a resource request? - Can I fetch a single access package by ID through a resource request's catalog? instructions: - text: Show access package {pkg} in the catalog of resource request {req}. slots: pkg: path.accessPackage-id req: path.accessPackageResourceRequest-id - text: Get details of access package {pkg} via request {req}'s catalog. slots: pkg: path.accessPackage-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/accessPackages/$count'].get update: x-apievangelist-phrasing: intent: Count access packages in a request's catalog effect: read questions: - How many access packages does the catalog on a resource request contain? - Is there a package total for the catalog tied to a resource request? instructions: - text: Count the access packages in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Tell me how many access packages request {req}'s catalog holds. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/customWorkflowExtensions'].get update: x-apievangelist-phrasing: intent: List custom workflow extensions in a request's catalog effect: read questions: - What custom workflow extensions (Logic Apps callouts) are defined in a resource request's catalog? - Can I list the callout extensions that fire in the catalog behind a resource request? instructions: - text: List custom workflow extensions in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show the callout extensions configured for request {req}'s catalog. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/customWorkflowExtensions'].post update: x-apievangelist-phrasing: intent: Add a custom workflow extension to a request's catalog effect: write questions: - How do I add a custom callout extension to the catalog of a resource request? - Can I register a Logic App endpoint as a workflow extension on a resource request's catalog? instructions: - text: Create a custom workflow extension named {name} in the catalog of resource request {req}. slots: name: requestBody.displayName req: path.accessPackageResourceRequest-id - text: Add a callout extension {name} with endpoint {endpoint} to request {req}'s catalog. slots: name: requestBody.displayName endpoint: requestBody.endpointConfiguration req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/customWorkflowExtensions/{customCalloutExtension-id}'].get update: x-apievangelist-phrasing: intent: Get a custom workflow extension in a request's catalog effect: read questions: - Where can I see the endpoint and authentication settings of one catalog callout extension? - Can I read a single custom workflow extension from a resource request's catalog? instructions: - text: Show custom workflow extension {ext} in the catalog of resource request {req}. slots: ext: path.customCalloutExtension-id req: path.accessPackageResourceRequest-id - text: Get the configuration of callout extension {ext} via request {req}'s catalog. slots: ext: path.customCalloutExtension-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/customWorkflowExtensions/{customCalloutExtension-id}'].delete update: x-apievangelist-phrasing: intent: Delete a custom workflow extension from a request's catalog effect: destructive questions: - Can I remove a custom callout extension from the catalog behind a resource request? - Is removing a callout extension from a request's catalog irreversible? instructions: - text: Delete custom workflow extension {ext} from the catalog of resource request {req}. slots: ext: path.customCalloutExtension-id req: path.accessPackageResourceRequest-id - text: Remove callout extension {ext} from request {req}'s catalog. slots: ext: path.customCalloutExtension-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/customWorkflowExtensions/{customCalloutExtension-id}'].patch update: x-apievangelist-phrasing: intent: Update a custom workflow extension in a request's catalog effect: write questions: - How do I change the endpoint of an existing catalog callout extension? - Can I rename a custom workflow extension in a resource request's catalog? instructions: - text: Rename custom workflow extension {ext} in the catalog of resource request {req} to {name}. slots: ext: path.customCalloutExtension-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Point callout extension {ext} of request {req}'s catalog at endpoint {endpoint}. slots: ext: path.customCalloutExtension-id req: path.accessPackageResourceRequest-id endpoint: requestBody.endpointConfiguration method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/customWorkflowExtensions/$count'].get update: x-apievangelist-phrasing: intent: Count custom workflow extensions in a request's catalog effect: read questions: - How many custom workflow extensions exist in a resource request's catalog? - Is there a total of callout extensions for the catalog on a resource request? instructions: - text: Count the custom workflow extensions in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Tell me how many callout extensions request {req}'s catalog has. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles'].get update: x-apievangelist-phrasing: intent: List resource roles in a request's catalog effect: read questions: - Which resource roles are available in the catalog a resource request targets? - Can I filter a catalog's resource roles by origin system, such as SharePoint or AAD groups? instructions: - text: List resource roles in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show the grantable resource roles of request {req}'s catalog. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles'].post update: x-apievangelist-phrasing: intent: Add a resource role to a request's catalog effect: write questions: - How do I register a new resource role in the catalog behind a resource request? - Can I add a role with an origin ID from the source system to a request's catalog? instructions: - text: Create resource role {name} with origin ID {origin} in the catalog of resource request {req}. slots: name: requestBody.displayName origin: requestBody.originId req: path.accessPackageResourceRequest-id - text: Add a resource role named {name} to request {req}'s catalog. slots: name: requestBody.displayName req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a resource role in a request's catalog effect: read questions: - Where do I read the origin system and type of one catalog resource role? - Can I look up a single resource role in a resource request's catalog? instructions: - text: Show resource role {role} in the catalog of resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Get details of catalog resource role {role} for request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a resource role from a request's catalog effect: destructive questions: - Can I remove a resource role from the catalog on a resource request? - Is there an If-Match check I can use when deleting a catalog resource role? instructions: - text: Delete resource role {role} from the catalog of resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Remove catalog resource role {role} under request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource role in a request's catalog effect: write questions: - How do I rename or re-describe a resource role in a request's catalog? - Can I change the origin ID recorded on a catalog resource role? instructions: - text: Rename resource role {role} in the catalog of resource request {req} to {name}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set the description of catalog resource role {role} (request {req}) to {desc}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id desc: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource behind a catalog resource role effect: read questions: - Which resource does a role in a resource request's catalog belong to? - Can I read the resource details starting from a resource role in a request's catalog? instructions: - text: Show the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Get the underlying resource for catalog resource role {role} in request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Delete the resource behind a catalog resource role effect: destructive questions: - Can I delete the resource linked to a catalog resource role? - What does removing the resource navigation from a catalog resource role do? instructions: - text: Delete the resource record behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Unlink and remove the underlying resource of catalog resource role {role} in request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource behind a catalog resource role effect: write questions: - How do I rename the resource that a catalog resource role points at? - Can I edit the description of a resource through its catalog resource role? instructions: - text: Update the display name of the resource behind resource role {role} of request {req} to {name}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the underlying resource of catalog resource role {role} in request {req}. slots: desc: requestBody.description role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of the resource behind a catalog role effect: read questions: - Which resource environment hosts the resource behind a catalog resource role? - Can I see the origin environment of a role's resource by going through a resource request? instructions: - text: Show the environment hosting the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Get environment info for the underlying resource of catalog resource role {role} in request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource behind a catalog resource role effect: write questions: - How do I resync the resource behind a catalog resource role with its origin system? - Can I pull the latest roles and scopes for a catalog resource role's resource? instructions: - text: Refresh the resource behind resource role {role} of request {req} from its origin. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Resync the underlying resource of catalog resource role {role} in request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of the resource behind a catalog resource role effect: read questions: - Working from a resource request, what other roles does the resource behind one of its catalog's roles offer? - Can I enumerate the sibling roles of a catalog resource role's resource? instructions: - text: List the roles offered by the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show every role on the underlying resource of catalog resource role {role} in request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to the resource behind a catalog resource role effect: write questions: - How do I add a new role to the resource behind a catalog resource role? - Can I create a sibling role with an origin ID on a catalog resource role's resource? instructions: - text: Add a role named {name} to the resource behind resource role {role} of request {req}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Create role {name} with origin ID {origin} on the underlying resource of catalog resource role {role} (request {req}). slots: name: requestBody.displayName origin: requestBody.originId role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/roles/{accessPackageResourceRole-id1}'].get update: x-apievangelist-phrasing: intent: Get a sibling role of a catalog resource role effect: read questions: - Where can I read one sibling role on the resource behind a catalog resource role? - Can I look up a second role by ID on a catalog resource role's resource? instructions: - text: Look up the details of sibling role {role2} next to resource role {role} of request {req}. slots: role2: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Get sibling role {role2} on the underlying resource of catalog resource role {role} (request {req}). slots: role2: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/roles/{accessPackageResourceRole-id1}'].delete update: x-apievangelist-phrasing: intent: Remove a sibling role of a catalog resource role effect: destructive questions: - Can I delete a sibling role from the resource behind a catalog resource role? - What is removed when I delete a second role on a catalog resource role's resource? instructions: - text: Remove role {role2} from the resource behind resource role {role} of request {req}. slots: role2: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Delete sibling role {role2} on the underlying resource of catalog resource role {role} (request {req}). slots: role2: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/roles/{accessPackageResourceRole-id1}'].patch update: x-apievangelist-phrasing: intent: Update a sibling role of a catalog resource role effect: write questions: - How do I rename a sibling role on the resource behind a catalog resource role? - Can I change the description of another role on a catalog resource role's resource? instructions: - text: Rename role {role2} of the resource behind resource role {role} of request {req} to {name}. slots: role2: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on sibling role {role2} of catalog resource role {role}'s resource (request {req}). slots: desc: requestBody.description role2: path.accessPackageResourceRole-id1 role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of the resource behind a catalog resource role effect: read questions: - Through a resource request's catalog, how many roles does a role's underlying resource expose? - Is there a role total for a catalog resource role's underlying resource? instructions: - text: Count the roles available on the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Tell me how many roles the underlying resource of catalog resource role {role} (request {req}) has. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a catalog role's resource effect: read questions: - Which access scopes are defined on the resource behind a catalog resource role? - Can I see whether a catalog resource role's resource has a root scope among its scopes? instructions: - text: Enumerate all access scopes for the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Which scopes exist under catalog resource role {role}'s underlying resource in request {req}? List them. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a catalog role's resource effect: write questions: - How do I define a new access scope under the resource behind a catalog resource role? - Can I flag a newly defined scope as the root scope for a catalog resource role's resource? instructions: - text: Define access scope {name} under the resource behind resource role {role} of request {req}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Register scope {name} with root-scope flag {root} beneath catalog resource role {role}'s underlying resource ({req}). slots: name: requestBody.displayName root: requestBody.isRootScope role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope of a catalog role's resource effect: read questions: - Where do I read one access scope defined under the resource behind a catalog resource role? - Can I check if a given scope on a catalog resource role's resource is flagged as root? instructions: - text: Look up scope {scope} details, including its root flag, on the resource behind resource role {role} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Fetch access scope {scope} defined beneath catalog resource role {role}'s underlying resource (request {req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Remove a scope from a catalog role's resource effect: destructive questions: - Can I drop an access scope defined under the resource behind a catalog resource role? - What goes away when a scope definition is dropped from a catalog resource role's resource? instructions: - text: Drop access scope {scope} defined under the resource behind resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Permanently delete scope definition {scope} beneath catalog resource role {role}'s underlying resource ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope of a catalog role's resource effect: write questions: - How do I relabel an access scope defined under the resource behind a catalog resource role? - Can I edit a scope definition's description on a catalog resource role's resource? instructions: - text: Relabel access scope {scope} under the resource behind resource role {role} of request {req} as {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Change scope definition {scope}'s description to {desc} beneath catalog resource role {role}'s resource ({req}). slots: scope: path.accessPackageResourceScope-id desc: requestBody.description role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource at a scope under a catalog resource role effect: read questions: - Via a resource request, which resource does a scope under its catalog's resource role point to? - Can I read resource details from a scope nested beneath a catalog resource role? instructions: - text: Show the resource at scope {scope} under resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Get the scope-level resource for scope {scope} nested beneath catalog resource role {role} (request {req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Delete the resource at a scope under a catalog resource role effect: destructive questions: - Can I delete the resource reached through a scope under a catalog resource role? - What does removing the scope-level resource beneath a catalog resource role affect? instructions: - text: Delete the resource record at scope {scope} under resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Remove the scope-level resource of scope {scope} nested beneath catalog resource role {role} (request {req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource at a scope under a catalog resource role effect: write questions: - How do I rename the resource reached through a scope under a catalog resource role? - Can I edit the description of a scope-level resource beneath a catalog resource role? instructions: - text: Update the display name of the resource at scope {scope} under resource role {role} of request {req} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the scope-level resource of scope {scope} beneath catalog resource role {role} (request {req}). slots: desc: requestBody.description scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a role-scope resource effect: read questions: - Which environment hosts the resource at a scope under a catalog resource role? - Can I see origin environment info for a scope-level resource beneath a catalog resource role? instructions: - text: Show the environment hosting the resource at scope {scope} under resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Get environment info for the scope-level resource of scope {scope} beneath catalog resource role {role} (request {req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a role-scope resource effect: write questions: - How do I resync the resource at a scope under a catalog resource role with its origin? - Can I refresh a scope-level resource nested beneath a catalog resource role? instructions: - text: Refresh the resource at scope {scope} under resource role {role} of request {req} from its origin. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Resync the scope-level resource of scope {scope} beneath catalog resource role {role} (request {req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of the resource at a scope under a catalog role effect: read questions: - What roles does the resource at a scope under a catalog resource role offer? - Can I enumerate roles on a scope-level resource nested beneath a catalog resource role? instructions: - text: List the roles offered by the resource at scope {scope} under resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show every role on the scope-level resource of scope {scope} beneath catalog resource role {role} (request {req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to the resource at a scope under a catalog role effect: write questions: - How do I add a role to the resource at a scope under a catalog resource role? - Can I create a role with an origin ID on a scope-level resource beneath a catalog resource role? instructions: - text: Add a role named {name} to the resource at scope {scope} under resource role {role} of request {req}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Create role {name} with origin {origin} on scope {scope}'s resource beneath catalog resource role {role} ({req}). slots: name: requestBody.displayName origin: requestBody.originId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id1}'].get update: x-apievangelist-phrasing: intent: Get a role of the resource at a scope under a catalog role effect: read questions: - Where can I read one role of the resource at a scope under a catalog resource role? - Can I look up a role by ID on a scope-level resource nested beneath a catalog resource role? instructions: - text: Look up role {role2} details for the resource at scope {scope} under resource role {role} ({req}). slots: role2: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Through request {req}, fetch second role {role2} at scope {scope} reached from resource role {role}. slots: role2: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id1}'].delete update: x-apievangelist-phrasing: intent: Remove a role from a role-scope resource effect: destructive questions: - Can I delete a role from the resource at a scope under a catalog resource role? - What is removed when a role goes from a scope-level resource beneath a catalog resource role? instructions: - text: Remove role {role2} from the resource at scope {scope} under resource role {role} of request {req}. slots: role2: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Delete role {role2} on scope {scope}'s resource beneath catalog resource role {role} ({req}). slots: role2: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id1}'].patch update: x-apievangelist-phrasing: intent: Update a role on a role-scope resource effect: write questions: - How do I rename a role on the resource at a scope under a catalog resource role? - Can I change the description of a role on a scope-level resource beneath a catalog resource role? instructions: - text: Rename role {role2} of the resource at scope {scope} under resource role {role} of request {req} to {name}. slots: role2: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on role {role2} of scope {scope}'s resource beneath catalog role {role} ({req}). slots: desc: requestBody.description role2: path.accessPackageResourceRole-id1 scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of the resource at a scope under a catalog role effect: read questions: - How many roles does the resource at a scope under a catalog resource role expose? - Is there a role total for a scope-level resource nested beneath a catalog resource role? instructions: - text: Count the roles available on the resource at scope {scope} under resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Tell me how many roles scope {scope}'s resource beneath catalog resource role {role} ({req}) has. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a role-scope resource effect: read questions: - What BYOD upload sessions exist for the resource at a scope under a catalog resource role? - Can I see every data upload started for a scope-level resource beneath a catalog resource role? instructions: - text: List upload sessions for the resource at scope {scope} under resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show all bring-your-own-data uploads opened for scope {scope}'s resource beneath catalog role {role} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a role-scope resource effect: write questions: - How do I start a BYOD upload session for the resource at a scope under a catalog resource role? - Can I open a data upload with a reference ID on a scope-level resource beneath a catalog resource role? instructions: - text: Open a new upload session for the resource at scope {scope} under resource role {role} of request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Start a data upload with reference {ref} for scope {scope}'s resource beneath catalog role {role} ({req}). slots: ref: requestBody.referenceId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a role-scope resource effect: read questions: - What is the status of one upload session on the resource at a scope under a catalog resource role? - Can I check if a BYOD upload on a scope-level resource beneath a catalog resource role is done? instructions: - text: Show details of upload session {sess} for the resource at scope {scope} under resource role {role} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Check whether upload session {sess} on scope {scope}'s resource beneath catalog role {role} ({req}) is done. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a role-scope resource effect: destructive questions: - Can I remove an upload session from the resource at a scope under a catalog resource role? - What happens when a BYOD upload session on a scope-level resource beneath a catalog role is deleted? instructions: - text: Delete upload session {sess} from the resource at scope {scope} under resource role {role} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Remove the stale upload session {sess} on scope {scope}'s resource beneath catalog role {role} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a role-scope resource effect: write questions: - How do I mark an upload session on the resource at a scope under a catalog resource role as finished? - Can I change the reference ID of a BYOD session on a scope-level resource beneath a catalog role? instructions: - text: Mark upload session {sess} for scope {scope}'s resource under resource role {role} ({req}) as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id done: requestBody.isUploadDone - text: Set reference {ref} on upload session {sess} of scope {scope}'s resource beneath catalog role {role} ({req}). slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List upload files of a role-scope resource effect: read questions: - Which files were uploaded in a BYOD session for the resource at a scope under a catalog resource role? - Can I sort the files of an upload session on a scope-level resource beneath a catalog role? instructions: - text: List files uploaded in session {sess} for scope {scope}'s resource under resource role {role} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show every file sent through session {sess} on scope {scope}'s resource beneath catalog role {role} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get an upload file of a role-scope resource effect: read questions: - Where do I see metadata of one file uploaded for the resource at a scope under a catalog resource role? - Can I look up a single uploaded file on a scope-level resource beneath a catalog role? instructions: - text: Show metadata for uploaded file {file} in session {sess} for scope {scope}'s resource under role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Look up file {file} of session {sess} on scope {scope}'s resource beneath catalog role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content for a role-scope resource effect: read questions: - How can I download the data of a file uploaded for the resource at a scope under a catalog resource role? - Is a file's original content retrievable from a scope-level resource beneath a catalog role? instructions: - text: Download the raw bytes of file {file} in session {sess} for scope {scope}'s resource under role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Fetch the stored data of file {file} (session {sess}) on scope {scope}'s resource beneath catalog role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content for a role-scope resource effect: write questions: - Can I overwrite a file already uploaded for the resource at a scope under a catalog resource role? - How do I re-upload corrected data into a file on a scope-level resource beneath a catalog role? instructions: - text: Overwrite file {file} with new content in session {sess} for scope {scope}'s resource under role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Put corrected data into file {file} (session {sess}) on scope {scope}'s resource beneath catalog role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content for a role-scope resource effect: destructive questions: - Can I erase the data of one file uploaded for the resource at a scope under a catalog resource role? - What removes the stored bytes of a BYOD file on a scope-level resource beneath a catalog role? instructions: - text: Erase the stored content of file {file} in session {sess} for scope {scope}'s resource under role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Clear the data held in file {file} (session {sess}) on scope {scope}'s resource beneath catalog role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count upload files of a role-scope resource effect: read questions: - How many files were uploaded in a session for the resource at a scope under a catalog resource role? - Is there a file total for an upload session on a scope-level resource beneath a catalog role? instructions: - text: Count the files uploaded to session {sess} for scope {scope}'s resource under resource role {role} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Tell me the number of files in session {sess} on scope {scope}'s resource beneath catalog role {role} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file for a role-scope resource effect: write questions: - How do I push an access data file into a session for the resource at a scope under a catalog resource role? - Can I add another data file to an open upload on a scope-level resource beneath a catalog role? instructions: - text: Upload a data file into session {sess} for scope {scope}'s resource under resource role {role} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Send a new access data file through session {sess} on scope {scope}'s resource beneath catalog role {role} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a role-scope resource effect: read questions: - How many BYOD upload sessions exist for the resource at a scope under a catalog resource role? - Can I tally the data uploads ever started on a scope-level resource beneath a catalog role? instructions: - text: Count how many upload sessions the resource at scope {scope} under resource role {role} ({req}) has. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Give me the number of BYOD upload sessions on scope {scope}'s resource beneath catalog role {role} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of the resource behind a catalog resource role effect: read questions: - What number of access scopes are defined under the resource behind a catalog resource role? - Can I get a scope count for a catalog resource role's resource without listing every scope? instructions: - text: Tally the access scopes defined under the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Report the scope definition count beneath catalog resource role {role}'s underlying resource ({req}). slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of the resource behind a catalog role effect: read questions: - What BYOD upload sessions exist for the resource behind a catalog resource role? - Can I see every data upload opened against a catalog resource role's underlying resource? instructions: - text: List upload sessions for the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show all bring-your-own-data uploads on the underlying resource of catalog resource role {role} (request {req}). slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a catalog role's resource effect: write questions: - How do I start a BYOD upload session for the resource behind a catalog resource role? - Can I open a data upload with a reference ID on a catalog resource role's underlying resource? instructions: - text: Open a new upload session for the resource behind resource role {role} of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Start a data upload with reference {ref} on the underlying resource of catalog resource role {role} (request {req}). slots: ref: requestBody.referenceId role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of the resource behind a catalog role effect: read questions: - What is the status of one upload session on the resource behind a catalog resource role? - Can I check whether a BYOD upload on a catalog resource role's underlying resource finished? instructions: - text: Show details of upload session {sess} for the resource behind resource role {role} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Check whether upload session {sess} on catalog resource role {role}'s underlying resource (request {req}) is done. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a catalog role's resource effect: destructive questions: - Can I remove an upload session from the resource behind a catalog resource role? - What happens when a BYOD session on a catalog resource role's underlying resource is deleted? instructions: - text: Delete upload session {sess} from the resource behind resource role {role} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Remove the stale upload session {sess} on catalog resource role {role}'s underlying resource (request {req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a catalog role's resource effect: write questions: - How do I mark an upload session on the resource behind a catalog resource role as finished? - Can I change the reference ID of a BYOD session on a catalog resource role's underlying resource? instructions: - text: Mark upload session {sess} for the resource behind resource role {role} of request {req} as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id done: requestBody.isUploadDone - text: Set reference {ref} on upload session {sess} of catalog resource role {role}'s underlying resource (request {req}). slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List upload files of a catalog role's resource effect: read questions: - Which files were uploaded in a BYOD session for the resource behind a catalog resource role? - Can I sort the files of an upload session on a catalog resource role's underlying resource? instructions: - text: List files uploaded in session {sess} for the resource behind resource role {role} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show every file sent through session {sess} on catalog resource role {role}'s underlying resource (request {req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get an upload file of a catalog role's resource effect: read questions: - Where do I see metadata of one file uploaded for the resource behind a catalog resource role? - Can I look up a single uploaded file on a catalog resource role's underlying resource? instructions: - text: Show metadata for uploaded file {file} in session {sess} for the resource behind resource role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Look up file {file} of session {sess} on catalog resource role {role}'s underlying resource (request {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content for a catalog role's resource effect: read questions: - How can I download the data of a file uploaded for the resource behind a catalog resource role? - Is a file's original content retrievable from a catalog resource role's underlying resource? instructions: - text: Download the raw bytes of file {file} in session {sess} for the resource behind resource role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Fetch the stored data of file {file} (session {sess}) on catalog resource role {role}'s underlying resource ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content for a catalog role's resource effect: write questions: - Can I overwrite a file already uploaded for the resource behind a catalog resource role? - How do I re-upload corrected data into a file on a catalog resource role's underlying resource? instructions: - text: Overwrite file {file} with new content in session {sess} for the resource behind resource role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Put corrected data into file {file} (session {sess}) on catalog resource role {role}'s underlying resource ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content for a catalog role's resource effect: destructive questions: - Can I erase the data of one file uploaded for the resource behind a catalog resource role? - What removes the stored bytes of a BYOD file on a catalog resource role's underlying resource? instructions: - text: Erase the stored content of file {file} in session {sess} for the resource behind resource role {role} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Clear the data held in file {file} (session {sess}) on catalog resource role {role}'s underlying resource ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count upload files of a catalog role's resource effect: read questions: - How many files were uploaded in a session for the resource behind a catalog resource role? - Is there a file total for an upload session on a catalog resource role's underlying resource? instructions: - text: Count the files uploaded to session {sess} for the resource behind resource role {role} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Tell me the number of files in session {sess} on catalog resource role {role}'s underlying resource ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file for a catalog role's resource effect: write questions: - How do I push an access data file into a session for the resource behind a catalog resource role? - Can I add another data file to an open upload on a catalog resource role's underlying resource? instructions: - text: Upload a data file into session {sess} for the resource behind resource role {role} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Send a new access data file through session {sess} on catalog resource role {role}'s underlying resource ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of the resource behind a catalog role effect: read questions: - How many BYOD upload sessions exist for the resource behind a catalog resource role? - Can I tally the data uploads ever started on a catalog resource role's underlying resource? instructions: - text: Count how many upload sessions the resource behind resource role {role} of request {req} has. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Give me the number of BYOD upload sessions on catalog resource role {role}'s underlying resource ({req}). slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceRoles/$count'].get update: x-apievangelist-phrasing: intent: Count resource roles in a request's catalog effect: read questions: - How many resource roles does the catalog behind a resource request contain? - Is there a quick total of grantable resource roles in a request's catalog? instructions: - text: Count the resource roles in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Tell me how many grantable resource roles request {req}'s catalog holds. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources'].get update: x-apievangelist-phrasing: intent: List resources in a request's catalog effect: read questions: - Which groups, apps and sites are registered as resources in the catalog a resource request targets? - Can I filter the catalog resources of a resource request by origin system? instructions: - text: List the resources registered in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show every catalog resource available through request {req}. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources'].post update: x-apievangelist-phrasing: intent: Add a resource to a request's catalog effect: write questions: - How do I register a resource directly in the catalog behind a resource request? - Can I add a resource with its origin ID and origin system to a request's catalog? instructions: - text: Register resource {name} with origin ID {origin} in the catalog of resource request {req}. slots: name: requestBody.displayName origin: requestBody.originId req: path.accessPackageResourceRequest-id - text: Put a new resource called {name} into the catalog of request {req}. slots: name: requestBody.displayName req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}'].get update: x-apievangelist-phrasing: intent: Get a resource in a request's catalog effect: read questions: - Where do I read one resource registered in the catalog of a resource request? - Can I see a catalog resource's origin system and attributes by its ID? instructions: - text: Show catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get details of resource {res} in request {req}'s catalog. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}'].delete update: x-apievangelist-phrasing: intent: Delete a resource from a request's catalog effect: destructive questions: - Can I delete a resource record from the catalog behind a resource request? - Is deleting a resource from a request's catalog a permanent removal? instructions: - text: Delete catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove resource {res} from request {req}'s catalog permanently. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource in a request's catalog effect: write questions: - How do I rename a resource registered in a resource request's catalog? - Can I edit the description of a catalog resource? instructions: - text: Update the display name of catalog resource {res} of request {req} to {name}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on resource {res} in request {req}'s catalog. slots: desc: requestBody.description res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a catalog resource effect: read questions: - Which resource environment does a catalog resource come from? - Can I see the origin environment details of a resource in a request's catalog? instructions: - text: Show the environment hosting catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get environment info for resource {res} in request {req}'s catalog. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a catalog resource from its origin effect: write questions: - How do I resync a catalog resource with its origin system after roles changed? - Can I refresh a resource in a request's catalog to pick up new roles and scopes? instructions: - text: Refresh catalog resource {res} of request {req} from its origin. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Resync resource {res} in request {req}'s catalog. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles'].get update: x-apievangelist-phrasing: intent: List roles of a catalog resource effect: read questions: - What roles does a catalog resource offer, such as owner or member? - Can I enumerate the grantable roles on a resource in a request's catalog? instructions: - text: List the roles offered by catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show every role on resource {res} in request {req}'s catalog. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a catalog resource effect: write questions: - How do I add a new role to a catalog resource? - Can I create a role with an origin ID on a resource in a request's catalog? instructions: - text: Add a role named {name} to catalog resource {res} of request {req}. slots: name: requestBody.displayName res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Create role {name} with origin ID {origin} on resource {res} in request {req}'s catalog. slots: name: requestBody.displayName origin: requestBody.originId res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role of a catalog resource effect: read questions: - From a resource request, where can I read one role of a resource in its catalog? - Can I look up a catalog resource's role by ID to check its origin system? instructions: - text: Look up role {role} details on catalog resource {res} of request {req}. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get role {role} of resource {res} in request {req}'s catalog. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Remove a role from a catalog resource effect: destructive questions: - Can I delete a role from a resource while working through a resource request's catalog? - What is removed when a role is deleted from a resource in a request's catalog? instructions: - text: Remove role {role} from catalog resource {res} of request {req}. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Delete role {role} on resource {res} in request {req}'s catalog. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role of a catalog resource effect: write questions: - How do I rename a role on a catalog resource? - Can I change the description of a role on a resource in a request's catalog? instructions: - text: Rename role {role} of catalog resource {res} of request {req} to {name}. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on role {role} of resource {res} in request {req}'s catalog. slots: desc: requestBody.description role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the target resource of a catalog resource's role effect: read questions: - Which resource does a role granted on a catalog resource point back to? - Can I read the target resource of a role granted on a catalog resource? instructions: - text: Show the resource behind role {role} granted on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get the target resource via granted role {role} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Delete the target resource of a catalog resource's role effect: destructive questions: - Can I delete the target resource linked from a role granted on a catalog resource? - What does removing the resource navigation of a catalog resource's role affect? instructions: - text: Delete the resource record behind role {role} granted on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the target resource via granted role {role} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the target resource of a catalog resource's role effect: write questions: - How do I rename the target resource of a role granted on a catalog resource? - Can I edit the description of the resource a catalog resource's role points to? instructions: - text: Update the display name of the resource behind role {role} granted on catalog resource {res} ({req}) to {name}. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the target resource via granted role {role} of catalog resource {res} ({req}). slots: desc: requestBody.description role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a role-granted target resource effect: read questions: - Which environment hosts the target resource of a role granted on a catalog resource? - Can I see origin environment info through a catalog resource's role? instructions: - text: Show the environment hosting the resource behind role {role} granted on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get environment info for the target resource via granted role {role} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the target resource of a catalog resource's role effect: write questions: - Is there a way to pull fresh origin-system data into the target resource of a role granted on a catalog resource? - Can I refresh the resource reached through a catalog resource's role from its origin? instructions: - text: Refresh the resource behind role {role} granted on catalog resource {res} ({req}) from its origin. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Resync the target resource via granted role {role} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a role-granted target resource effect: read questions: - Which access scopes are defined on the target resource of a role granted on a catalog resource? - Can I see whether the resource behind a catalog resource's role has a root scope? instructions: - text: Enumerate all access scopes for the resource behind role {role} granted on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Which scopes exist via granted role {role} of catalog resource {res} ({req})? List them. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a role-granted target resource effect: write questions: - How do I define a new access scope under the target resource of a role granted on a catalog resource? - Can I flag a new scope as root on the resource behind a catalog resource's role? instructions: - text: Define access scope {name} under the resource behind role {role} granted on catalog resource {res} ({req}). slots: name: requestBody.displayName role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Register scope {name} with root-scope flag {root} via granted role {role} of catalog resource {res} ({req}). slots: name: requestBody.displayName root: requestBody.isRootScope role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope of a role-granted target resource effect: read questions: - Where do I read one access scope under the target resource of a role granted on a catalog resource? - Can I check if a scope on the resource behind a catalog resource's role is flagged as root? instructions: - text: Look up scope {scope} details on the resource behind role {role} granted on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Fetch access scope {scope} via granted role {role} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Remove a scope from a role-granted target resource effect: destructive questions: - Can I drop an access scope under the target resource of a role granted on a catalog resource? - Is dropping a scope definition under a role-granted target resource permanent? instructions: - text: Drop access scope {scope} under the resource behind role {role} granted on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Permanently delete scope definition {scope} via granted role {role} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope of a role-granted target resource effect: write questions: - How do I relabel an access scope under the target resource of a role granted on a catalog resource? - Can I edit a scope definition's description via a catalog resource's role? instructions: - text: Relabel access scope {scope} under the resource behind role {role} granted on catalog resource {res} ({req}) as {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Change scope definition {scope}'s description to {desc} via granted role {role} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id desc: requestBody.description role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource at a scope of a catalog resource's role effect: read questions: - Which resource sits at a scope reached from a role on a catalog resource? - Can I read the target resource at a scope reached from a role on a catalog resource? instructions: - text: Show the resource at scope {scope} reached from role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get the target resource via role {role} and its child scope {scope} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Delete the resource at a scope of a catalog resource's role effect: destructive questions: - Can I delete the resource at a scope reached from a role on a catalog resource? - What does removing the resource at a role's child scope on a catalog resource affect? instructions: - text: Delete the resource record at scope {scope} reached from role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the target resource via role {role} and its child scope {scope} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource at a scope of a catalog resource's role effect: write questions: - How do I rename the resource at a scope reached from a role on a catalog resource? - Can I edit the description of the resource at a role's child scope on a catalog resource? instructions: - text: Update the display name of the resource at scope {scope} reached from role {role} on resource {res} ({req}) to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the target via role {role} and its child scope {scope} of catalog resource {res} ({req}). slots: desc: requestBody.description role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment at a role's child scope resource effect: read questions: - Which environment hosts the resource at a scope reached from a role on a catalog resource? - Can I see origin environment info for a role's child scope on a catalog resource? instructions: - text: Show the environment hosting the resource at scope {scope} reached from role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get environment info via role {role} and its child scope {scope} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource at a role's child scope effect: write questions: - Is there a way to pull fresh origin-system data into the resource at a scope reached from a role on a catalog resource? - Can I refresh the target resource at a role's child scope on a catalog resource from its origin? instructions: - text: Refresh the resource at scope {scope} reached from role {role} on catalog resource {res} ({req}) from its origin. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Resync the target via role {role} and its child scope {scope} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions at a role's child scope resource effect: read questions: - What BYOD upload sessions exist for the resource at a scope reached from a role on a catalog resource? - Can I see every data upload opened against a role's child scope on a catalog resource? instructions: - text: List upload sessions for the resource at scope {scope} reached from role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show all bring-your-own-data uploads via role {role} and its child scope {scope} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session at a role's child scope resource effect: write questions: - How do I start a BYOD upload session for the resource at a scope reached from a role on a catalog resource? - Can I open a data upload with a reference ID at a role's child scope on a catalog resource? instructions: - text: Open a new upload session for the resource at scope {scope} reached from role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Start a data upload with reference {ref} via role {role} and its child scope {scope} of resource {res} ({req}). slots: ref: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session at a role's child scope resource effect: read questions: - What is the status of one upload session on the resource at a scope reached from a role on a catalog resource? - Can I check whether a BYOD upload at a role's child scope on a catalog resource finished? instructions: - text: Show details of upload session {sess} at scope {scope} reached from role {role} on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Check whether upload session {sess} via role {role} and its child scope {scope} of resource {res} ({req}) is done. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session at a role's child scope resource effect: destructive questions: - Can I remove an upload session from the resource at a scope reached from a role on a catalog resource? - What happens when a BYOD session at a role's child scope on a catalog resource is deleted? instructions: - text: Delete upload session {sess} at scope {scope} reached from role {role} on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the stale upload session {sess} via role {role} and its child scope {scope} of resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session at a role's child scope resource effect: write questions: - How do I mark an upload session at a scope reached from a role on a catalog resource as finished? - Can I change the reference ID of a BYOD session at a role's child scope on a catalog resource? instructions: - text: Mark upload session {sess} at scope {scope} reached from role {role} on resource {res} ({req}) as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id done: requestBody.isUploadDone - text: Set reference {ref} on upload session {sess} via role {role} and its child scope {scope} of resource {res} ({req}). slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload session at a role's child scope effect: read questions: - Which files were uploaded in a BYOD session at a scope reached from a role on a catalog resource? - Can I sort the files of an upload session at a role's child scope on a catalog resource? instructions: - text: List files uploaded in session {sess} at scope {scope} reached from role {role} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show every file sent through session {sess} via role {role} and its child scope {scope} of resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file in an upload session at a role's child scope effect: read questions: - Where do I see metadata of one file uploaded at a scope reached from a role on a catalog resource? - Can I look up a single uploaded file at a role's child scope on a catalog resource? instructions: - text: Show metadata for file {file} in session {sess} at scope {scope} reached from role {role} on resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Look up file {file} of session {sess} via role {role} and its child scope {scope} of resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content at a role's child scope resource effect: read questions: - How can I download the data of a file uploaded at a scope reached from a role on a catalog resource? - Is a file's original content retrievable at a role's child scope on a catalog resource? instructions: - text: Download the raw bytes of file {file} in session {sess} at scope {scope} reached from role {role} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Fetch the stored data of file {file} (session {sess}) via role {role} and its child scope {scope} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content at a role's child scope resource effect: write questions: - Can I overwrite a file already uploaded at a scope reached from a role on a catalog resource? - How do I re-upload corrected data into a file at a role's child scope on a catalog resource? instructions: - text: Overwrite file {file} with new content in session {sess} at scope {scope} reached from role {role} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Put corrected data into file {file} (session {sess}) via role {role} and its child scope {scope} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content at a role's child scope resource effect: destructive questions: - Can I erase the data of one file uploaded at a scope reached from a role on a catalog resource? - What removes the stored bytes of a BYOD file at a role's child scope on a catalog resource? instructions: - text: Erase the stored content of file {file} in session {sess} at scope {scope} reached from role {role} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Clear the data held in file {file} (session {sess}) via role {role} and its child scope {scope} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload session at a role's child scope effect: read questions: - How many files were uploaded in a session at a scope reached from a role on a catalog resource? - Is there a file total for an upload session at a role's child scope on a catalog resource? instructions: - text: Count the files uploaded to session {sess} at scope {scope} reached from role {role} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Tell me the number of files in session {sess} via role {role} and its child scope {scope} of resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file at a role's child scope resource effect: write questions: - How do I push an access data file into a session at a scope reached from a role on a catalog resource? - Can I add another data file to an open upload at a role's child scope on a catalog resource? instructions: - text: Upload a data file into session {sess} at scope {scope} reached from role {role} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Send a new access data file through session {sess} via role {role} and its child scope {scope} ({res}, {req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions at a role's child scope resource effect: read questions: - How many BYOD upload sessions exist for the resource at a scope reached from a role on a catalog resource? - Can I tally the data uploads ever started at a role's child scope on a catalog resource? instructions: - text: Count how many upload sessions the resource at scope {scope} reached from role {role} on resource {res} ({req}) has. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Give me the number of BYOD upload sessions via role {role} and its child scope {scope} of resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a role-granted target resource effect: read questions: - What number of access scopes are defined under the target resource of a role granted on a catalog resource? - Is there a cheap way to size up the scopes under a role-granted target resource? instructions: - text: Tally the access scopes defined under the resource behind role {role} granted on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Report the scope definition count via granted role {role} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a role-granted target resource effect: read questions: - What BYOD upload sessions exist for the target resource of a role granted on a catalog resource? - Can I see every data upload opened through a catalog resource's granted role? instructions: - text: List upload sessions for the resource behind role {role} granted on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show all bring-your-own-data uploads via granted role {role} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a role-granted target resource effect: write questions: - How do I start a BYOD upload session for the target resource of a role granted on a catalog resource? - Can I open a data upload with a reference ID through a catalog resource's granted role? instructions: - text: Open a new upload session for the resource behind role {role} granted on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Start a data upload with reference {ref} via granted role {role} of catalog resource {res} ({req}). slots: ref: requestBody.referenceId role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a role-granted target resource effect: read questions: - What is the status of one upload session on the target resource of a role granted on a catalog resource? - Can I check whether a BYOD upload through a catalog resource's granted role finished? instructions: - text: Show details of upload session {sess} for the resource behind role {role} granted on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Check whether upload session {sess} via granted role {role} of catalog resource {res} ({req}) is done. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a role-granted target resource effect: destructive questions: - Can I remove an upload session from the target resource of a role granted on a catalog resource? - What happens when a BYOD session through a catalog resource's granted role is deleted? instructions: - text: Delete upload session {sess} from the resource behind role {role} granted on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the stale upload session {sess} via granted role {role} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a role-granted target resource effect: write questions: - How do I mark an upload session on the target resource of a role granted on a catalog resource as finished? - Can I change the reference ID of a BYOD session through a catalog resource's granted role? instructions: - text: Mark upload session {sess} for the resource behind role {role} granted on resource {res} ({req}) as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id done: requestBody.isUploadDone - text: Set reference {ref} on upload session {sess} via granted role {role} of catalog resource {res} ({req}). slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload session of a role-granted resource effect: read questions: - Which files were uploaded in a BYOD session for the target resource of a role granted on a catalog resource? - Can I sort the files of an upload session through a catalog resource's granted role? instructions: - text: List files uploaded in session {sess} for the resource behind role {role} granted on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show every file sent through session {sess} via granted role {role} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file in an upload session of a role-granted resource effect: read questions: - Where do I see metadata of one file uploaded for the target resource of a role granted on a catalog resource? - Can I look up a single uploaded file through a catalog resource's granted role? instructions: - text: Show metadata for file {file} in session {sess} for the resource behind role {role} granted on resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Look up file {file} of session {sess} via granted role {role} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content of a role-granted target resource effect: read questions: - How can I download the data of a file uploaded for the target resource of a role granted on a catalog resource? - Is a file's original content retrievable through a catalog resource's granted role? instructions: - text: Download the raw bytes of file {file} in session {sess} for the target resource behind role {role} granted on catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Fetch the stored data of file {file} (session {sess}) via granted role {role} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content of a role-granted target resource effect: write questions: - Can I overwrite a file already uploaded for the target resource of a role granted on a catalog resource? - How do I re-upload corrected data into a file through a catalog resource's granted role? instructions: - text: Overwrite file {file} with new content in session {sess} for the target resource behind role {role} granted on catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Put corrected data into file {file} (session {sess}) via granted role {role} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content of a role-granted target resource effect: destructive questions: - Can I erase the data of one file uploaded for the target resource of a role granted on a catalog resource? - What removes the stored bytes of a BYOD file through a catalog resource's granted role? instructions: - text: Erase the stored content of file {file} in session {sess} for the target resource behind role {role} granted on catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Clear the data held in file {file} (session {sess}) via granted role {role} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload session of a role-granted resource effect: read questions: - How many files were uploaded in a session for the target resource of a role granted on a catalog resource? - Is there a file total for an upload session through a catalog resource's granted role? instructions: - text: Count the files uploaded to session {sess} for the resource behind role {role} granted on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Tell me the number of files in session {sess} via granted role {role} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file to a role-granted target resource effect: write questions: - How do I push an access data file into a session for the target resource of a role granted on a catalog resource? - Can I add another data file to an open upload through a catalog resource's granted role? instructions: - text: Upload a data file into session {sess} for the resource behind role {role} granted on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Send a new access data file through session {sess} via granted role {role} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a role-granted target resource effect: read questions: - How many BYOD upload sessions exist for the target resource of a role granted on a catalog resource? - Can I tally the data uploads ever started through a catalog resource's granted role? instructions: - text: Count how many upload sessions the resource behind role {role} granted on catalog resource {res} ({req}) has. slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Give me the number of BYOD upload sessions via granted role {role} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a catalog resource effect: read questions: - How many roles does a catalog resource expose? - Is there a role total for a resource in a request's catalog? instructions: - text: Count the roles available on catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Tell me how many roles resource {res} in request {req}'s catalog has. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a catalog resource effect: read questions: - Which access scopes are defined on a catalog resource? - Can I see whether a resource in a request's catalog has a root scope among its scopes? instructions: - text: Enumerate all access scopes for catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Which scopes exist under resource {res} in request {req}'s catalog? List them. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a catalog resource effect: write questions: - How do I define a new access scope under a catalog resource? - Can I flag a newly defined scope as the root scope for a resource in a request's catalog? instructions: - text: Define access scope {name} under catalog resource {res} of request {req}. slots: name: requestBody.displayName res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Register scope {name} with root-scope flag {root} beneath resource {res} in request {req}'s catalog. slots: name: requestBody.displayName root: requestBody.isRootScope res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope of a catalog resource effect: read questions: - Where do I read one access scope defined under a catalog resource? - Can I check if a given scope on a resource in a request's catalog is flagged as root? instructions: - text: Look up scope {scope} details, including its root flag, on catalog resource {res} of request {req}. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Fetch access scope {scope} defined beneath resource {res} in request {req}'s catalog. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Remove a scope from a catalog resource effect: destructive questions: - Can I drop an access scope defined under a catalog resource? - What goes away when a scope definition is dropped from a resource in a request's catalog? instructions: - text: Drop access scope {scope} defined under catalog resource {res} of request {req}. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Permanently delete scope definition {scope} beneath resource {res} in request {req}'s catalog. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope of a catalog resource effect: write questions: - How do I relabel an access scope defined under a catalog resource? - Can I edit a scope definition's description on a resource in a request's catalog? instructions: - text: Relabel access scope {scope} under catalog resource {res} of request {req} as {name}. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Change scope definition {scope}'s description to {desc} beneath resource {res} in request {req}'s catalog. slots: scope: path.accessPackageResourceScope-id desc: requestBody.description res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the target resource of a catalog resource's scope effect: read questions: - Which resource does a scope defined on a catalog resource point back to? - Can I read the target resource of a scope defined on a catalog resource? instructions: - text: Show the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get the target resource via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Delete the target resource of a catalog resource's scope effect: destructive questions: - Can I delete the target resource linked from a scope defined on a catalog resource? - What does removing the resource navigation of a catalog resource's scope affect? instructions: - text: Delete the resource record behind scope {scope} defined on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the target resource via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the target resource of a catalog resource's scope effect: write questions: - How do I rename the target resource of a scope defined on a catalog resource? - Is the description of a scope-defined target resource editable from the catalog resource side? instructions: - text: Update the display name of the resource behind scope {scope} defined on catalog resource {res} ({req}) to {name}. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the target resource via defined scope {scope} of catalog resource {res} ({req}). slots: desc: requestBody.description scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a scope-defined target resource effect: read questions: - Which environment hosts the target resource of a scope defined on a catalog resource? - Can I see origin environment info through a catalog resource's scope? instructions: - text: Show the environment hosting the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get environment info for the target resource via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the target resource of a catalog resource's scope effect: write questions: - Is there a way to pull fresh origin-system data into the target resource of a scope defined on a catalog resource? - Can a resync be triggered for whatever resource a catalog resource's defined scope links to? instructions: - text: Refresh the resource behind scope {scope} defined on catalog resource {res} ({req}) from its origin. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Resync the target resource via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a scope-defined target resource effect: read questions: - What roles does the target resource of a scope defined on a catalog resource offer? - Can I enumerate the grantable roles through a catalog resource's scope? instructions: - text: List the roles offered by the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show every role via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a scope-defined target resource effect: write questions: - How do I add a new role to the target resource of a scope defined on a catalog resource? - Can I create a role with an origin ID through a catalog resource's scope? instructions: - text: Add a role named {name} to the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Create role {name} with origin ID {origin} via defined scope {scope} of catalog resource {res} ({req}). slots: name: requestBody.displayName origin: requestBody.originId scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role of a scope-defined target resource effect: read questions: - Where can I read one role on the target resource of a scope defined on a catalog resource? - Can I look up a role by ID through a catalog resource's scope? instructions: - text: Look up role {role} details on the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get role {role} via defined scope {scope} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Remove a role from a scope-defined target resource effect: destructive questions: - Can I delete a role from the target resource of a scope defined on a catalog resource? - What is removed when a role is deleted through a catalog resource's scope? instructions: - text: Remove role {role} from the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Delete role {role} via defined scope {scope} of catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role of a scope-defined target resource effect: write questions: - What's the way to give a new display name to one role under a scope-defined target resource? - Can I change the description of a role through a catalog resource's scope? instructions: - text: Rename role {role} of the resource behind scope {scope} defined on catalog resource {res} ({req}) to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on role {role} via defined scope {scope} of catalog resource {res} ({req}). slots: desc: requestBody.description role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource at a role of a catalog resource's scope effect: read questions: - Which resource sits at a role found within a scope on a catalog resource? - Can I read the target resource at a role found within a scope on a catalog resource? instructions: - text: Show the resource at role {role} found within scope {scope} on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get the target resource through scope {scope}'s nested role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Delete the resource at a role of a catalog resource's scope effect: destructive questions: - Can I delete the resource at a role found within a scope on a catalog resource? - What does removing the resource under a role listed beneath a catalog resource's scope affect? instructions: - text: Delete the resource record at role {role} found within scope {scope} on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the target resource through scope {scope}'s nested role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource at a role of a catalog resource's scope effect: write questions: - How do I rename the resource at a role found within a scope on a catalog resource? - Can I edit the description of the resource under a role listed beneath a catalog resource's scope? instructions: - text: Update the display name of the resource at role {role} found within scope {scope} on resource {res} ({req}) to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the target through scope {scope}'s nested role {role} on catalog resource {res} ({req}). slots: desc: requestBody.description scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment at a scope's nested role resource effect: read questions: - Which environment hosts the resource at a role found within a scope on a catalog resource? - Can I see origin environment info for a role listed beneath a catalog resource's scope? instructions: - text: Show the environment hosting the resource at role {role} found within scope {scope} on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Get environment info through scope {scope}'s nested role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource at a scope's nested role effect: write questions: - Is there a way to pull fresh origin-system data into the resource at a role found within a scope on a catalog resource? - Can I refresh the target resource under a role listed beneath a catalog resource's scope from its origin? instructions: - text: Refresh the resource at role {role} found within scope {scope} on catalog resource {res} ({req}) from its origin. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Resync the target through scope {scope}'s nested role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions at a scope's nested role resource effect: read questions: - What BYOD upload sessions exist for the resource at a role found within a scope on a catalog resource? - Can I see every data upload opened against a role listed beneath a catalog resource's scope? instructions: - text: List upload sessions for the resource at role {role} found within scope {scope} on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show all bring-your-own-data uploads through scope {scope}'s nested role {role} on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session at a scope's nested role resource effect: write questions: - How do I start a BYOD upload session for the resource at a role found within a scope on a catalog resource? - Can I open a data upload with a reference ID under a role listed beneath a catalog resource's scope? instructions: - text: Open a new upload session for the resource at role {role} found within scope {scope} on catalog resource {res} ({req}). slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Start a data upload with reference {ref} through scope {scope}'s nested role {role} on resource {res} ({req}). slots: ref: requestBody.referenceId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session at a scope's nested role resource effect: read questions: - What is the status of one upload session on the resource at a role found within a scope on a catalog resource? - Can I check whether a BYOD upload under a role listed beneath a catalog resource's scope finished? instructions: - text: Show details of upload session {sess} at role {role} found within scope {scope} on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Check whether upload session {sess} through scope {scope}'s nested role {role} on resource {res} ({req}) is done. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session at a scope's nested role resource effect: destructive questions: - Can I remove an upload session from the resource at a role found within a scope on a catalog resource? - What happens when a BYOD session under a role listed beneath a catalog resource's scope is deleted? instructions: - text: Delete upload session {sess} at role {role} found within scope {scope} on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the stale upload session {sess} through scope {scope}'s nested role {role} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session at a scope's nested role resource effect: write questions: - How do I mark an upload session at a role found within a scope on a catalog resource as finished? - Can I change the reference ID of a BYOD session under a role listed beneath a catalog resource's scope? instructions: - text: Mark upload session {sess} at role {role} found within scope {scope} on resource {res} ({req}) as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id done: requestBody.isUploadDone - text: Set reference {ref} on upload session {sess} through scope {scope}'s nested role {role} on resource {res} ({req}). slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload session at a scope's nested role effect: read questions: - Which files were uploaded in a BYOD session at a role found within a scope on a catalog resource? - Can I sort the files of an upload session under a role listed beneath a catalog resource's scope? instructions: - text: List files uploaded in session {sess} at role {role} found within scope {scope} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show every file sent through session {sess} via scope {scope}'s nested role {role} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file in an upload session at a scope's nested role effect: read questions: - Where do I see metadata of one file uploaded at a role found within a scope on a catalog resource? - Can I look up a single uploaded file under a role listed beneath a catalog resource's scope? instructions: - text: Show metadata for file {file} in session {sess} at role {role} found within scope {scope} on resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Look up file {file} of session {sess} through scope {scope}'s nested role {role} on resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content at a scope's nested role resource effect: read questions: - How can I download the data of a file uploaded at a role found within a scope on a catalog resource? - Is a file's original content retrievable under a role listed beneath a catalog resource's scope? instructions: - text: Download the raw bytes of file {file} in session {sess} at role {role} found within scope {scope} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Fetch the stored data of file {file} (session {sess}) through scope {scope}'s nested role {role} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content at a scope's nested role resource effect: write questions: - Can I overwrite a file already uploaded at a role found within a scope on a catalog resource? - How do I re-upload corrected data into a file under a role listed beneath a catalog resource's scope? instructions: - text: Overwrite file {file} with new content in session {sess} at role {role} found within scope {scope} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Put corrected data into file {file} (session {sess}) through scope {scope}'s nested role {role} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content at a scope's nested role resource effect: destructive questions: - Can I erase the data of one file uploaded at a role found within a scope on a catalog resource? - What removes the stored bytes of a BYOD file under a role listed beneath a catalog resource's scope? instructions: - text: Erase the stored content of file {file} in session {sess} at role {role} found within scope {scope} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Clear the data held in file {file} (session {sess}) through scope {scope}'s nested role {role} ({res}, {req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload session at a scope's nested role effect: read questions: - How many files were uploaded in a session at a role found within a scope on a catalog resource? - Is there a file total for an upload session under a role listed beneath a catalog resource's scope? instructions: - text: Count the files uploaded to session {sess} at role {role} found within scope {scope} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Tell me the number of files in session {sess} through scope {scope}'s nested role {role} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file at a scope's nested role resource effect: write questions: - How do I push an access data file into a session at a role found within a scope on a catalog resource? - Can I add another data file to an open upload under a role listed beneath a catalog resource's scope? instructions: - text: Upload a data file into session {sess} at role {role} found within scope {scope} on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Send a new access data file through session {sess} via scope {scope}'s nested role {role} ({res}, {req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions at a scope's nested role resource effect: read questions: - How many BYOD upload sessions exist for the resource at a role found within a scope on a catalog resource? - Can I tally the data uploads ever started under a role listed beneath a catalog resource's scope? instructions: - text: Count how many upload sessions the resource at role {role} found within scope {scope} on resource {res} ({req}) has. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Give me the number of BYOD upload sessions through scope {scope}'s nested role {role} on resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a scope-defined target resource effect: read questions: - How many roles does the target resource of a scope defined on a catalog resource expose? - Is there a role total through a catalog resource's scope? instructions: - text: Count the roles available on the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Tell me how many roles exist via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a scope-defined target resource effect: read questions: - What BYOD upload sessions exist for the target resource of a scope defined on a catalog resource? - Can I see every data upload opened through a catalog resource's defined scope? instructions: - text: List upload sessions for the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show all bring-your-own-data uploads via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a scope-defined target resource effect: write questions: - How do I start a BYOD upload session for the target resource of a scope defined on a catalog resource? - Can I open a data upload with a reference ID through a catalog resource's defined scope? instructions: - text: Open a new upload session for the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Start a data upload with reference {ref} via defined scope {scope} of catalog resource {res} ({req}). slots: ref: requestBody.referenceId scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a scope-defined target resource effect: read questions: - What is the status of one upload session on the target resource of a scope defined on a catalog resource? - Can I check whether a BYOD upload through a catalog resource's defined scope finished? instructions: - text: Show details of upload session {sess} for the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Check whether upload session {sess} via defined scope {scope} of catalog resource {res} ({req}) is done. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a scope-defined target resource effect: destructive questions: - Can I remove an upload session from the target resource of a scope defined on a catalog resource? - What happens when a BYOD session through a catalog resource's defined scope is deleted? instructions: - text: Delete upload session {sess} from the resource behind scope {scope} defined on catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the stale upload session {sess} via defined scope {scope} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a scope-defined target resource effect: write questions: - How do I mark an upload session on the target resource of a scope defined on a catalog resource as finished? - Can I change the reference ID of a BYOD session through a catalog resource's defined scope? instructions: - text: Mark upload session {sess} for the resource behind scope {scope} defined on resource {res} ({req}) as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id done: requestBody.isUploadDone - text: Set reference {ref} on upload session {sess} via defined scope {scope} of catalog resource {res} ({req}). slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload session of a scope-defined resource effect: read questions: - Which files were uploaded in a BYOD session for the target resource of a scope defined on a catalog resource? - Can I sort the files of an upload session through a catalog resource's defined scope? instructions: - text: List files uploaded in session {sess} for the resource behind scope {scope} defined on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show every file sent through session {sess} via defined scope {scope} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file in an upload session of a scope-defined resource effect: read questions: - Where do I see metadata of one file uploaded for the target resource of a scope defined on a catalog resource? - Can I look up a single uploaded file through a catalog resource's defined scope? instructions: - text: Show metadata for file {file} in session {sess} for the resource behind scope {scope} defined on resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Look up file {file} of session {sess} via defined scope {scope} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content of a scope-defined target resource effect: read questions: - How can I download the data of a file uploaded for the target resource of a scope defined on a catalog resource? - Is a file's original content retrievable through a catalog resource's defined scope? instructions: - text: Download the raw bytes of file {file} in session {sess} for the target resource behind scope {scope} defined on catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Fetch the stored data of file {file} (session {sess}) via defined scope {scope} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content of a scope-defined target resource effect: write questions: - Can I overwrite a file already uploaded for the target resource of a scope defined on a catalog resource? - How do I re-upload corrected data into a file through a catalog resource's defined scope? instructions: - text: Overwrite file {file} with new content in session {sess} for the target resource behind scope {scope} defined on catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Put corrected data into file {file} (session {sess}) via defined scope {scope} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content of a scope-defined target resource effect: destructive questions: - Can I erase the data of one file uploaded for the target resource of a scope defined on a catalog resource? - What removes the stored bytes of a BYOD file through a catalog resource's defined scope? instructions: - text: Erase the stored content of file {file} in session {sess} for the target resource behind scope {scope} defined on catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Clear the data held in file {file} (session {sess}) via defined scope {scope} of catalog resource {res} ({req}). slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload session of a scope-defined resource effect: read questions: - How many files were uploaded in a session for the target resource of a scope defined on a catalog resource? - Is there a file total for an upload session through a catalog resource's defined scope? instructions: - text: Count the files uploaded to session {sess} for the resource behind scope {scope} defined on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Tell me the number of files in session {sess} via defined scope {scope} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file to a scope-defined target resource effect: write questions: - How do I push an access data file into a session for the target resource of a scope defined on a catalog resource? - Can I add another data file to an open upload through a catalog resource's defined scope? instructions: - text: Upload a data file into session {sess} for the resource behind scope {scope} defined on resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Send a new access data file through session {sess} via defined scope {scope} of catalog resource {res} ({req}). slots: sess: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a scope-defined target resource effect: read questions: - How many BYOD upload sessions exist for the target resource of a scope defined on a catalog resource? - Can I tally the data uploads ever started through a catalog resource's defined scope? instructions: - text: Count how many upload sessions the resource behind scope {scope} defined on catalog resource {res} ({req}) has. slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Give me the number of BYOD upload sessions via defined scope {scope} of catalog resource {res} ({req}). slots: scope: path.accessPackageResourceScope-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a catalog resource effect: read questions: - What number of access scopes are defined under a resource registered directly in a catalog? - Can I get a scope count for a resource in a request's catalog without listing every scope? instructions: - text: Tally the access scopes defined under catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Report the scope definition count beneath resource {res} in request {req}'s catalog. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a catalog resource effect: read questions: - What BYOD upload sessions exist for a resource registered directly in a catalog? - Can I see every data upload opened against a resource in a request's catalog? instructions: - text: List upload sessions for catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show all bring-your-own-data uploads on resource {res} in request {req}'s catalog. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a catalog resource effect: write questions: - How do I start a BYOD upload session for a resource registered directly in a catalog? - Can I open a data upload with a reference ID on a resource in a request's catalog? instructions: - text: Open a new upload session for catalog resource {res} of request {req}. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Start a data upload with reference {ref} on resource {res} in request {req}'s catalog. slots: ref: requestBody.referenceId res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a catalog resource effect: read questions: - What is the status of one upload session on a resource registered directly in a catalog? - Can I check whether a BYOD upload on a resource in a request's catalog finished? instructions: - text: Show details of upload session {sess} for catalog resource {res} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Check whether upload session {sess} on resource {res} in request {req}'s catalog is done. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a catalog resource effect: destructive questions: - Can I remove an upload session from a resource registered directly in a catalog? - What happens when a BYOD session on a resource in a request's catalog is deleted? instructions: - text: Delete upload session {sess} from catalog resource {res} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Remove the stale upload session {sess} on resource {res} in request {req}'s catalog. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a catalog resource effect: write questions: - How do I mark an upload session on a catalog resource as finished? - Can I change the reference ID of a BYOD session on a resource in a request's catalog? instructions: - text: Mark upload session {sess} for catalog resource {res} of request {req} as upload done {done}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id done: requestBody.isUploadDone - text: Set reference {ref} on upload session {sess} of resource {res} in request {req}'s catalog. slots: ref: requestBody.referenceId sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in an upload session of a catalog resource effect: read questions: - Which files were uploaded in a BYOD session for a resource registered directly in a catalog? - Can I sort the files of an upload session on a resource in a request's catalog? instructions: - text: List files uploaded in session {sess} for catalog resource {res} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Show every file sent through session {sess} on resource {res} in request {req}'s catalog. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get a file in an upload session of a catalog resource effect: read questions: - Where do I see metadata of one file uploaded for a resource registered directly in a catalog? - Can I look up a single uploaded file on a resource in a request's catalog? instructions: - text: Show metadata for uploaded file {file} in session {sess} for catalog resource {res} of request {req}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Look up file {file} of session {sess} on resource {res} in request {req}'s catalog. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content of a catalog resource effect: read questions: - How can I download the data of a file uploaded for a resource registered directly in a catalog? - Is a file's original content retrievable from a resource in a request's catalog? instructions: - text: Download the raw bytes of file {file} in session {sess} for catalog resource {res} of request {req}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Fetch the stored data of file {file} (session {sess}) on resource {res} in request {req}'s catalog. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content of a catalog resource effect: write questions: - Can I overwrite a file already uploaded for a resource registered directly in a catalog? - How do I re-upload corrected data into a file on a resource in a request's catalog? instructions: - text: Overwrite file {file} with new content in session {sess} for catalog resource {res} of request {req}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Put corrected data into file {file} (session {sess}) on resource {res} in request {req}'s catalog. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content of a catalog resource effect: destructive questions: - Can I erase the data of one file uploaded for a resource registered directly in a catalog? - What removes the stored bytes of a BYOD file on a resource in a request's catalog? instructions: - text: Erase the stored content of file {file} in session {sess} for catalog resource {res} of request {req}. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Clear the data held in file {file} (session {sess}) on resource {res} in request {req}'s catalog. slots: file: path.customDataProvidedResourceFile-id sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in an upload session of a catalog resource effect: read questions: - How many files were uploaded in a session for a resource registered directly in a catalog? - Is there a file total for an upload session on a resource in a request's catalog? instructions: - text: Count the files uploaded to session {sess} for catalog resource {res} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Tell me the number of files in session {sess} on resource {res} in request {req}'s catalog. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a data file to a catalog resource effect: write questions: - How do I push an access data file into a session for a resource registered directly in a catalog? - Can I add another data file to an open upload on a resource in a request's catalog? instructions: - text: Upload a data file into session {sess} for catalog resource {res} of request {req}. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Send a new access data file through session {sess} on resource {res} in request {req}'s catalog. slots: sess: path.customDataProvidedResourceUploadSession-id res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/{accessPackageResource-id}/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a catalog resource effect: read questions: - How many BYOD upload sessions exist for a resource registered directly in a catalog? - Can I tally the data uploads ever started on a resource in a request's catalog? instructions: - text: Count how many upload sessions catalog resource {res} of request {req} has. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id - text: Give me the number of BYOD upload sessions on resource {res} in request {req}'s catalog. slots: res: path.accessPackageResource-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resources/$count'].get update: x-apievangelist-phrasing: intent: Count resources in a request's catalog effect: read questions: - How many resources are registered in the catalog a resource request targets? - Is there a quick total of catalog resources for a resource request? instructions: - text: Count the resources in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Tell me how many catalog resources request {req}'s catalog holds. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes'].get update: x-apievangelist-phrasing: intent: List resource scopes in a request's catalog effect: read questions: - Which resource scopes are available across the catalog a resource request targets? - Can I filter a catalog's resource scopes to find the root scopes? instructions: - text: List resource scopes in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show every resource scope of request {req}'s catalog. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes'].post update: x-apievangelist-phrasing: intent: Add a resource scope to a request's catalog effect: write questions: - Where do I create a catalog-level resource scope for a resource request? - Can I add a root resource scope with an origin ID to a request's catalog? instructions: - text: Create resource scope {name} with origin ID {origin} in the catalog of resource request {req}. slots: name: requestBody.displayName origin: requestBody.originId req: path.accessPackageResourceRequest-id - text: Add a resource scope named {name} with root flag {root} to request {req}'s catalog. slots: name: requestBody.displayName root: requestBody.isRootScope req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a resource scope in a request's catalog effect: read questions: - Where do I read one resource scope from the catalog of a resource request? - Can I check whether a catalog resource scope is the root scope? instructions: - text: Show resource scope {scope} in the catalog of resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Get details of catalog resource scope {scope} for request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a resource scope from a request's catalog effect: destructive questions: - Can I remove a resource scope from the catalog on a resource request? - Can I guard deletion of a catalog resource scope with an ETag? instructions: - text: Delete resource scope {scope} from the catalog of resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Remove catalog resource scope {scope} under request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a catalog resource scope via a resource request effect: write questions: - How do I rename a resource scope in the catalog that an access package resource request targets? - Can I flag a catalog resource scope as the root scope while working from a resource request? instructions: - text: Rename catalog scope {scope} on resource request {req} to {name}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set isRootScope to {root} for catalog scope {scope} of request {req}. slots: root: requestBody.isRootScope scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource at a request's catalog scope effect: read questions: - Which resource does a catalog scope point to for a given access package resource request? - What display name and origin does the resource at a request's catalog scope have? instructions: - text: Show the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Fetch origin details of the catalog scope {scope} resource on resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource at a request's catalog scope effect: destructive questions: - Can I detach the resource linked to a catalog scope inside a resource request? - What removes the resource reference sitting at a request's catalog scope? instructions: - text: Delete the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Unlink the resource from catalog scope {scope} in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource at a request's catalog scope effect: write questions: - How do I change the description of the resource at a catalog scope in a resource request? - Can I edit which requestor attributes the catalog scope resource of a request collects? instructions: - text: Set description {desc} on the resource at catalog scope {scope} of request {req}. slots: desc: requestBody.description scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Rename the catalog scope {scope} resource in resource request {req} to {name}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a request's catalog scope resource effect: read questions: - Which environment does the resource at a resource request's catalog scope live in? - Can I see environment details for the resource reached through a request's catalog scope? instructions: - text: Get the environment for the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show the hosting environment of catalog scope {scope}'s resource in request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource at a request's catalog scope effect: write questions: - How do I refresh the resource sitting at a resource request's catalog scope? - Can I trigger the refresh action on a catalog scope resource of an access package request? instructions: - text: Refresh the resource at catalog scope {scope} for resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Run the refresh action on catalog scope {scope}'s resource in request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a request's catalog scope resource effect: read questions: - What roles does the resource at a resource request's catalog scope offer? - Can I expand the roles listed on a catalog scope resource of a request? instructions: - text: List roles on the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show every role the catalog scope {scope} resource offers in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a request's catalog scope resource effect: write questions: - How do I add a role to the resource at a catalog scope in a resource request? - Can I give an origin ID when creating a role on a request's catalog scope resource? instructions: - text: Create role {name} on the resource at catalog scope {scope} of request {req}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Add a role with origin ID {origin} to catalog scope {scope}'s resource in request {req}. slots: origin: requestBody.originId scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get one role of a request's catalog scope resource effect: read questions: - What are the details of a single role on a resource request's catalog scope resource? - Which origin system does one specific role at a catalog scope resource come from? instructions: - text: Get role {role} on the resource at catalog scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show origin system and type of role {role} for catalog scope {scope} in request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role from a request's catalog scope resource effect: destructive questions: - How do I remove a role from the resource at a request's catalog scope? - Can I delete a single role listed on a catalog scope resource of a resource request? instructions: - text: Delete role {role} from the resource at catalog scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Remove role {role} from catalog scope {scope}'s resource in resource request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a request's catalog scope resource effect: write questions: - How do I rename a role on the resource at a resource request's catalog scope? - Can I change the description of one role on a catalog scope resource? instructions: - text: Rename role {role} on catalog scope {scope}'s resource in request {req} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Update the description of role {role} to {desc} at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id desc: requestBody.description scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource owning a role at a catalog scope effect: read questions: - Which resource owns a given role at a resource request's catalog scope? - Can I read the parent resource of a catalog scope role in an access package request? instructions: - text: Get the resource that owns role {role} at catalog scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show the parent resource of role {role} in catalog scope {scope}, resource request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the owning resource from a catalog scope role effect: destructive questions: - Can I remove the resource reference from a role at a request's catalog scope? - What deletes the owning-resource link on a catalog scope role in a resource request? instructions: - text: Delete the owning resource link of role {role} at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Detach the parent resource from role {role} in catalog scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource owning a catalog scope role effect: write questions: - How do I rename the resource that owns a role at a request's catalog scope? - Can I update the description of a catalog scope role's owning resource? instructions: - text: Rename the owning resource of role {role} at catalog scope {scope}, request {req} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on role {role}'s parent resource, catalog scope {scope}, request {req}. slots: desc: requestBody.description role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a catalog scope role's resource effect: read questions: - Which environment hosts the resource owning a role at a request's catalog scope? - Can I fetch environment info for a catalog scope role's owning resource? instructions: - text: Get the environment of role {role}'s owning resource at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show which environment hosts role {role}'s parent resource in catalog scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource owning a catalog scope role effect: write questions: - Is there an action that refreshes the parent resource of a role under a request's catalog scope? - Can I trigger refresh on a catalog scope role's parent resource? instructions: - text: Refresh the owning resource of role {role} at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Run refresh on role {role}'s parent resource for catalog scope {scope} in request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a catalog scope role's resource effect: read questions: - What scopes exist on the resource owning a role at a request's catalog scope? - Can I list the scopes of a catalog scope role's parent resource? instructions: - text: List scopes on role {role}'s owning resource at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show all scopes of role {role}'s parent resource in catalog scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a catalog scope role's resource effect: write questions: - How do I add a scope to the resource owning a role at a request's catalog scope? - Can I create a root scope on a catalog scope role's parent resource? instructions: - text: Create scope {name} on role {role}'s owning resource at catalog scope {scope}, request {req}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Create a root scope ({root}) on role {role}'s parent resource under catalog scope {scope}, request {req}. slots: root: requestBody.isRootScope role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id1}'].get update: x-apievangelist-phrasing: intent: Get one scope of a catalog scope role's resource effect: read questions: - What are the details of one scope on a catalog scope role's owning resource? - Is a given scope on a request's catalog scope role resource marked as the root scope? instructions: - text: Get scope {scope2} on role {role}'s owning resource at catalog scope {scope}, request {req}. slots: scope2: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Check whether scope {scope2} of role {role}'s parent resource is root, catalog scope {scope}, request {req}. slots: scope2: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id1}'].delete update: x-apievangelist-phrasing: intent: Delete a scope from a catalog scope role's resource effect: destructive questions: - How do I delete a scope from the resource owning a role at a request's catalog scope? - Can I remove one scope from a catalog scope role's parent resource? instructions: - text: Delete scope {scope2} from role {role}'s owning resource at catalog scope {scope}, request {req}. slots: scope2: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Remove scope {scope2} on role {role}'s parent resource in catalog scope {scope} of request {req}. slots: scope2: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id1}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a catalog scope role's resource effect: write questions: - Can I retitle one of the scopes on a catalog scope role's owning resource? - Can I change the origin system of a scope on a catalog scope role's parent resource? instructions: - text: Rename scope {scope2} on role {role}'s owning resource (catalog scope {scope}, request {req}) to {name}. slots: scope2: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set origin system {system} on scope {scope2} of role {role}'s parent resource, catalog scope {scope}, request {req}. slots: system: requestBody.originSystem scope2: path.accessPackageResourceScope-id1 role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a catalog scope role's resource effect: read questions: - How many scopes does the resource owning a role at a request's catalog scope have? - Can I get just the scope total for a catalog scope role's parent resource? instructions: - text: Count scopes on role {role}'s owning resource at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the scope total for role {role}'s parent resource in catalog scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a catalog scope role's resource effect: read questions: - Which upload sessions exist for the resource owning a role at a request's catalog scope? - Can I list external access data uploads for a catalog scope role's parent resource? instructions: - text: List upload sessions on role {role}'s owning resource at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show external access data upload sessions for role {role}'s parent resource, catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session for a catalog scope role's resource effect: write questions: - How do I start an upload session for the resource owning a role at a request's catalog scope? - Can I pass an access review reference ID when opening an upload session for a catalog scope role's resource? instructions: - text: Start an upload session for role {role}'s owning resource at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Open an upload session with reference ID {refid} for role {role}'s parent resource, catalog scope {scope}, request {req}. slots: refid: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a catalog scope role's resource effect: read questions: - What state is one upload session in for a catalog scope role's owning resource? - Has a given upload session for a request's catalog scope role resource finished uploading? instructions: - text: Get upload session {session} for role {role}'s owning resource at catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Check if upload session {session} is complete for role {role}'s parent resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a catalog scope role's resource effect: destructive questions: - How do I delete an upload session on the resource owning a role at a request's catalog scope? - Can I discard one external data upload session for a catalog scope role's parent resource? instructions: - text: Delete upload session {session} from role {role}'s owning resource at catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Discard upload session {session} on role {role}'s parent resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a catalog scope role's resource effect: write questions: - How do I mark an upload session as done for a catalog scope role's owning resource? - Can I change the status of an upload session on a request's catalog scope role resource? instructions: - text: Mark upload session {session} as done ({done}) for role {role}'s owning resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Set status {status} on upload session {session} of role {role}'s parent resource, catalog scope {scope}, request {req}. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalog scope role resource's upload session effect: read questions: - Which files were uploaded in a session for the resource owning a role at a request's catalog scope? - Can I list the files in one upload session of a catalog scope role's parent resource? instructions: - text: List files in upload session {session} for role {role}'s owning resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show the uploaded files of session {session} on role {role}'s parent resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a catalog scope role resource's session effect: read questions: - What metadata does one uploaded file have in a catalog scope role resource's upload session? - Can I look up a single file record in an upload session under a request's catalog scope role? instructions: - text: Get file {file} in upload session {session} for role {role}'s owning resource, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show metadata for file {file} from session {session}, role {role}'s parent resource, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a catalog scope role resource's session effect: read questions: - How do I download the bytes of an uploaded file for a catalog scope role's owning resource? - Can I read the raw media content of a file uploaded under a request's catalog scope role? instructions: - text: Download the stored bytes of file {file}, session {session}, role {role}'s owning resource, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Fetch raw media content of file {file} in session {session} for role {role}, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a catalog scope role's session effect: write questions: - What call swaps in new content for an existing file under a catalog scope role's resource? - Can I overwrite a file's media content in an upload session under a request's catalog scope role? instructions: - text: Replace the content of file {file} with new bytes, session {session}, role {role}, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Overwrite media content of file {file} in session {session} for role {role}'s resource, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear file content in a catalog scope role's session effect: destructive questions: - How do I delete the media content of an uploaded file for a catalog scope role's owning resource? - Can I wipe a file's bytes but keep the upload session under a request's catalog scope role? instructions: - text: Wipe out file {file}'s content, leaving upload session {session} intact, role {role}, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Erase media content of file {file} in session {session} for role {role}, catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a catalog scope role resource's session effect: read questions: - How many files are in one upload session for a catalog scope role's owning resource? - Can I get only the file total of an upload session under a request's catalog scope role? instructions: - text: Tell me how many files session {session} holds for role {role}'s owning resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the file total of session {session} on role {role}'s parent resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a catalog scope role resource's session effect: write questions: - How do I upload a file into a session created for a catalog scope role's owning resource? - Can I push an external access data file to a resource request's catalog scope role resource? instructions: - text: Upload a file into session {session} for role {role}'s owning resource at catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Push a data file to upload session {session}, role {role}'s parent resource, catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a catalog scope role's resource effect: read questions: - How many upload sessions does the resource owning a role at a request's catalog scope have? - Can I get only the upload session total for a catalog scope role's parent resource? instructions: - text: Count upload sessions on role {role}'s owning resource at catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the upload session total for role {role}'s parent resource, catalog scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a request's catalog scope resource effect: read questions: - How many roles does the resource at a resource request's catalog scope offer? - Can I get only the role total for a catalog scope resource of a request? instructions: - text: Count roles on the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the role total for catalog scope {scope}'s resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a request's catalog scope resource effect: read questions: - What scopes does the resource at a resource request's catalog scope expose? - Can I list the scopes of a catalog scope resource directly, without going through a role? instructions: - text: List scopes on the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show all scopes exposed by catalog scope {scope}'s resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a request's catalog scope resource effect: write questions: - How do I add a new scope, root or not, to a catalog scope resource of a request? - Can I create a root scope on the catalog scope resource of an access package request? instructions: - text: Define new scope {name} on catalog scope {scope}'s resource for resource request {req}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Add a scope with isRootScope {root} to catalog scope {scope}'s resource in request {req}. slots: root: requestBody.isRootScope scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/{accessPackageResourceScope-id1}'].get update: x-apievangelist-phrasing: intent: Get one scope of a request's catalog scope resource effect: read questions: - What are the details of one scope on the resource at a request's catalog scope? - Which origin ID does a specific scope of a catalog scope resource carry? instructions: - text: Show details of scope {scope2} exposed by catalog scope {scope}'s resource, request {req}. slots: scope2: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show the origin ID of scope {scope2} for catalog scope {scope}'s resource in request {req}. slots: scope2: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/{accessPackageResourceScope-id1}'].delete update: x-apievangelist-phrasing: intent: Delete a scope from a request's catalog scope resource effect: destructive questions: - What removes a single scope exposed directly by a catalog scope resource? - Is it possible to drop one scope from the resource at an access package request's catalog scope? instructions: - text: Drop scope {scope2} from catalog scope {scope}'s resource on resource request {req}. slots: scope2: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Remove scope {scope2} exposed by catalog scope {scope}'s resource in resource request {req}. slots: scope2: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/{accessPackageResourceScope-id1}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a request's catalog scope resource effect: write questions: - What's the call to retitle a scope exposed by a request's catalog scope resource? - Can I update the description of one scope exposed by a catalog scope resource? instructions: - text: Rename scope {scope2} on the resource at catalog scope {scope} of request {req} to {name}. slots: scope2: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on scope {scope2} of catalog scope {scope}'s resource, request {req}. slots: desc: requestBody.description scope2: path.accessPackageResourceScope-id1 scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a request's catalog scope resource effect: read questions: - How many scopes does the resource at a resource request's catalog scope expose? - Is there a quick count of the scopes a catalog scope resource exposes? instructions: - text: Count scopes on the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the scope total exposed by catalog scope {scope}'s resource in request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a request's catalog scope resource effect: read questions: - Which upload sessions were opened directly on a request's catalog scope resource? - Can I see the external access data uploads made to a catalog scope resource of a request? instructions: - text: List upload sessions on the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show external data upload sessions for catalog scope {scope}'s resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a catalog scope resource effect: write questions: - How do I open an upload session for the resource at a catalog scope in a resource request? - Can I tag a new upload session on a catalog scope resource with an access review reference ID? instructions: - text: Start an upload session on the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Open an upload session tagged {refid} directly on catalog scope {scope}'s resource, request {req}. slots: refid: requestBody.referenceId scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a request's catalog scope resource effect: read questions: - What state is one upload session in for the resource at a request's catalog scope? - Has an upload session on a catalog scope resource of a resource request finished uploading? instructions: - text: Get upload session {session} on the resource at catalog scope {scope} of request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Check if upload session {session} is complete for catalog scope {scope}'s resource in request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete a catalog scope resource's upload session effect: destructive questions: - Can I delete an upload session opened directly on a request's catalog scope resource? - Can I discard one external data upload session for a catalog scope resource of a request? instructions: - text: Delete upload session {session} from the resource at catalog scope {scope} of request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Discard upload session {session} on catalog scope {scope}'s resource in resource request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update a catalog scope resource's upload session effect: write questions: - How do I mark an upload session as done for the resource at a request's catalog scope? - Can I set the status on an upload session opened directly on a catalog scope resource? instructions: - text: Mark upload session {session} as done ({done}) on the resource at catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Set status {status} on upload session {session} for catalog scope {scope}'s resource in request {req}. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalog scope resource's upload session effect: read questions: - Which files sit in an upload session opened directly on a request's catalog scope resource? - Can I list the files of one upload session on a catalog scope resource of a request? instructions: - text: List files in upload session {session} on the resource at catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show the uploaded files of session {session} for catalog scope {scope}'s resource in request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a catalog scope resource's upload session effect: read questions: - What metadata is stored for a file uploaded directly to a catalog scope resource? - Can I look up a single file record uploaded to a request's catalog scope resource? instructions: - text: Get file {file} in upload session {session} on the resource at catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show metadata for file {file} from session {session} of catalog scope {scope}'s resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a catalog scope resource's session effect: read questions: - How do I download the bytes of a file uploaded to the resource at a request's catalog scope? - Can I read the raw media content of a file in a catalog scope resource's upload session? instructions: - text: Download the stored bytes of file {file}, session {session}, resource at catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Fetch raw media of file {file} from session {session} on the resource at catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a catalog scope resource session effect: write questions: - What call swaps in new content for a file uploaded directly to a catalog scope resource? - Can I overwrite a file's media content in a catalog scope resource's upload session? instructions: - text: Replace file {file}'s content with new bytes in session {session} on the resource at catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Overwrite media content of file {file} in session {session} on catalog scope {scope}'s resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear a file's content in a catalog scope resource's session effect: destructive questions: - How do I delete the media content of a file uploaded to the resource at a request's catalog scope? - Can I wipe a file's bytes but keep the upload session on a catalog scope resource? instructions: - text: Wipe out file {file}'s content but keep session {session}, resource at catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Erase the media of file {file} from session {session} on the resource at catalog scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a catalog scope resource's upload session effect: read questions: - How many files are in one upload session for the resource at a request's catalog scope? - Can I get only the file total of a catalog scope resource's upload session? instructions: - text: Tell me how many files session {session} holds on the resource at catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the file total of session {session} for catalog scope {scope}'s resource in request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a catalog scope resource's session effect: write questions: - How do I upload a file into a session created for the resource at a request's catalog scope? - Can I push an external access data file to a catalog scope resource of a resource request? instructions: - text: Upload a file into session {session} on the resource at catalog scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Push a data file to upload session {session} for catalog scope {scope}'s resource in request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a request's catalog scope resource effect: read questions: - What's the number of upload sessions opened directly on a request's catalog scope resource? - Is there a count endpoint for upload sessions on a catalog scope resource? instructions: - text: Count upload sessions on the resource at catalog scope {scope} of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the upload session total for catalog scope {scope}'s resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/catalog/resourceScopes/$count'].get update: x-apievangelist-phrasing: intent: Count resource scopes in a request's catalog effect: read questions: - How many resource scopes does the catalog behind a resource request contain? - Can I get just the number of catalog resource scopes for an access package resource request? instructions: - text: Count the resource scopes in the catalog of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Return how many catalog resource scopes request {req} can see. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource named in a resource request effect: read questions: - Which resource is an access package resource request asking to add or change? - What display name and origin system does the requested resource of a resource request have? instructions: - text: Show the requested resource in resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Fetch display name and origin of the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the requested resource from a resource request effect: destructive questions: - Can I delete the resource reference held by an access package resource request? - What detaches the requested resource from a resource request record? instructions: - text: Delete the requested resource link on resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Detach the resource that request {req} points at. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the requested resource of a resource request effect: write questions: - How do I edit the description of the requested resource on a resource request? - Can I change the requestor attributes collected by the requested resource in a request? instructions: - text: Set description {desc} on the requested resource of resource request {req}. slots: desc: requestBody.description req: path.accessPackageResourceRequest-id - text: Rename the resource that request {req} is for to {name}. slots: req: path.accessPackageResourceRequest-id name: requestBody.displayName method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a request's requested resource effect: read questions: - Which environment is the requested resource of a resource request hosted in? - Can I read environment info for the resource an access package request targets? instructions: - text: Get the environment of the requested resource in resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show where the resource behind request {req} is hosted, environment-wise. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the requested resource of a resource request effect: write questions: - Is there an action to refresh the requested resource on a resource request? - Can I run refresh against the resource an access package resource request targets? instructions: - text: Refresh the requested resource of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Run the refresh action on the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a request's requested resource effect: read questions: - What roles does the requested resource of a resource request offer? - Can I list every assignable role on the resource an access package request targets? instructions: - text: List roles offered by the requested resource in resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show all roles on the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a request's requested resource effect: write questions: - How do I add a new role, with its type, to the requested resource of a resource request? - Can I set an origin system when creating a role on a request's requested resource? instructions: - text: Create role {name} of type {rtype} on the requested resource of request {req}. slots: name: requestBody.displayName rtype: requestBody.type req: path.accessPackageResourceRequest-id - text: Add a new role with origin ID {origin} to the resource that request {req} is for. slots: origin: requestBody.originId req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get one role of a request's requested resource effect: read questions: - What are the details of a single role on a resource request's requested resource? - Which origin ID does a specific role of the requested resource carry? instructions: - text: Get role {role} of the requested resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show details for role {role} on the resource that request {req} is for. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role from a request's requested resource effect: destructive questions: - Can I remove one role from the requested resource of a resource request? - What deletes a single role offered by the resource an access package request targets? instructions: - text: Delete role {role} from the requested resource of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Remove role {role} offered by the resource that request {req} is for. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a request's requested resource effect: write questions: - Can I rename a role offered by the requested resource of a resource request? - What changes the description on one role of a request's requested resource? instructions: - text: Rename role {role} on the requested resource of request {req} to {name}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on role {role} of the resource that request {req} is for. slots: desc: requestBody.description role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the home resource of a requested resource's role effect: read questions: - Which resource is the home of a given role on a resource request's requested resource? - Can I read the home resource that a requested resource's role belongs to? instructions: - text: Get the home resource of role {role} on the requested resource of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show which resource role {role} belongs to in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the home resource of a requested resource's role effect: destructive questions: - Can I delete the home resource reference on a role of a request's requested resource? - What removes the belongs-to resource link from a requested resource's role? instructions: - text: Delete the home resource link of role {role} in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Detach role {role}'s home resource on the requested resource of request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the home resource of a requested resource's role effect: write questions: - How do I rename the home resource of a role on a request's requested resource? - Can I edit the description of the resource a requested resource's role belongs to? instructions: - text: Rename role {role}'s home resource in resource request {req} to {name}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the home resource of role {role}, request {req}. slots: desc: requestBody.description role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a requested role's home resource effect: read questions: - Which environment hosts the home resource of a role on a request's requested resource? - Can I get environment details for the resource a requested resource's role belongs to? instructions: - text: Get the environment of role {role}'s home resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show which environment hosts the home resource of role {role}, request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the home resource of a requested resource's role effect: write questions: - Is there a refresh action for the home resource of a requested resource's role? - Can I trigger refresh on the resource a role of a resource request belongs to? instructions: - text: Refresh role {role}'s home resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Run refresh on the home resource of role {role} for request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a requested role's home resource effect: read questions: - What scopes does the home resource of a requested resource's role expose? - Can I list scopes on the resource a resource request role belongs to? instructions: - text: List scopes on role {role}'s home resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show all scopes exposed by the home resource of role {role}, request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a requested role's home resource effect: write questions: - How do I define a new scope on the home resource of a requested resource's role? - Can I create a root scope on the resource a request's role belongs to? instructions: - text: Create scope {name} on role {role}'s home resource in resource request {req}. slots: name: requestBody.displayName role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Define a new scope with isRootScope {root} on the home resource of role {role}, request {req}. slots: root: requestBody.isRootScope role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get one scope of a requested role's home resource effect: read questions: - What details does one scope on a requested role's home resource have? - Is a particular scope on the home resource of a request's role the root scope? instructions: - text: Get scope {scope} on role {role}'s home resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Check whether scope {scope} of the home resource of role {role} is root, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope from a requested role's home resource effect: destructive questions: - Can I delete one scope from the home resource of a requested resource's role? - What removes a single scope exposed by a request role's home resource? instructions: - text: Delete scope {scope} from role {role}'s home resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Drop scope {scope} exposed by the home resource of role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a requested role's home resource effect: write questions: - Can I retitle a scope on the home resource of a requested resource's role? - What changes the origin system of one scope on a request role's home resource? instructions: - text: Rename scope {scope} on role {role}'s home resource in request {req} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set origin system {system} on scope {scope} of role {role}'s home resource, request {req}. slots: system: requestBody.originSystem scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the backing resource of a nested scope under a role effect: read questions: - Which resource backs a nested scope under a role of a request's requested resource? - Can I read the backing resource of a scope nested under a requested resource's role? instructions: - text: Get the backing resource of nested scope {scope} under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show which resource backs scope {scope} nested under role {role} in resource request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the backing resource of a nested scope under a role effect: destructive questions: - Can I delete the backing resource link of a scope nested under a requested resource's role? - What detaches the resource behind a nested scope under a request's role? instructions: - text: Delete the backing resource link of nested scope {scope} under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Detach the resource behind scope {scope} nested under role {role} in request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the backing resource of a nested scope under a role effect: write questions: - How do I rename the backing resource of a scope nested under a requested resource's role? - Can I edit the description of the resource behind a nested scope under a request's role? instructions: - text: Rename the backing resource of nested scope {scope} under role {role}, request {req} to {name}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the resource behind scope {scope} nested under role {role}, request {req}. slots: desc: requestBody.description scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a nested scope's backing resource effect: read questions: - Which environment hosts the backing resource of a scope nested under a requested role? - Can I get environment info for the resource behind a nested scope under a request's role? instructions: - text: Get the environment of nested scope {scope}'s backing resource under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show which environment hosts the resource behind scope {scope} nested under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the backing resource of a nested scope under a role effect: write questions: - Is there a refresh action for the backing resource of a scope nested under a requested role? - Can I trigger refresh on the resource behind a nested scope under a request's role? instructions: - text: Refresh the backing resource of nested scope {scope} under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Run refresh on the resource behind scope {scope} nested under role {role} in request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a nested scope's backing resource effect: read questions: - Which upload sessions exist on the backing resource of a scope nested under a requested role? - Can I list external access data uploads for a nested scope's backing resource under a role? instructions: - text: List upload sessions on nested scope {scope}'s backing resource under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show external data upload sessions for the resource behind scope {scope} nested under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a nested scope's backing resource effect: write questions: - How do I open an upload session for the backing resource of a scope nested under a requested role? - Can I tag a new nested-scope upload session under a role with an access review reference ID? instructions: - text: Start an upload session on nested scope {scope}'s backing resource under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Open an upload session tagged {refid} for the resource behind scope {scope} nested under role {role}, request {req}. slots: refid: requestBody.referenceId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a nested scope's backing resource effect: read questions: - What state is one upload session in for a nested scope's backing resource under a requested role? - Has an upload session on the resource behind a scope nested under a role finished uploading? instructions: - text: Get upload session {session} on nested scope {scope}'s backing resource under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Check if upload session {session} is complete for scope {scope} nested under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete a nested scope resource's upload session effect: destructive questions: - Can I delete an upload session on the backing resource of a scope nested under a requested role? - What discards one external data upload session for a nested scope under a request's role? instructions: - text: Delete upload session {session} from nested scope {scope}'s backing resource under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Discard upload session {session} for the resource behind scope {scope} nested under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update a nested scope resource's upload session effect: write questions: - How do I mark an upload session as done for a nested scope's backing resource under a requested role? - Can I set the status on an upload session for a scope nested under a request's role? instructions: - text: Mark upload session {session} as done ({done}) on nested scope {scope}'s backing resource, role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Set status {status} on upload session {session} for scope {scope} nested under role {role}, request {req}. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a nested scope resource's upload session effect: read questions: - Which files sit in an upload session on the backing resource of a scope nested under a requested role? - Can I list files uploaded in one session for a nested scope under a request's role? instructions: - text: List files in upload session {session} on nested scope {scope}'s backing resource, role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show uploaded files of session {session} for scope {scope} nested under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a nested scope resource's upload session effect: read questions: - What metadata is stored for one file uploaded to a nested scope's backing resource under a requested role? - Can I look up a single file record in an upload session for a scope nested under a role? instructions: - text: Get file {file} in upload session {session} on nested scope {scope}'s backing resource, role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show metadata for file {file} from session {session}, scope {scope} nested under role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a nested scope resource's session effect: read questions: - How do I download the bytes of a file uploaded to a nested scope's backing resource under a requested role? - Can I read the raw media of a file in a session for a scope nested under a request's role? instructions: - text: Download the stored bytes of file {file}, session {session}, nested scope {scope} under role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Fetch raw media of file {file} from session {session} on the resource behind scope {scope} under role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a nested scope resource's session effect: write questions: - What call swaps in new content for a file uploaded to a nested scope's backing resource under a role? - Can I overwrite a file's media in an upload session for a scope nested under a request's role? instructions: - text: Replace file {file}'s content with new bytes in session {session}, nested scope {scope} under role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Overwrite media content of file {file} in session {session} for scope {scope} nested under role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear file content in a nested scope resource's session effect: destructive questions: - Can I wipe a file's bytes but keep the upload session for a nested scope's backing resource under a role? - What deletes the media content of a file uploaded for a scope nested under a request's role? instructions: - text: Wipe out file {file}'s content but keep session {session}, nested scope {scope} under role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Erase the media of file {file} from session {session} for scope {scope} nested under role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a nested scope resource's upload session effect: read questions: - How many files does one upload session hold for a nested scope's backing resource under a requested role? - Is there a file count for an upload session on a scope nested under a request's role? instructions: - text: Tell me how many files session {session} holds for nested scope {scope} under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Return the file total of upload session {session}, scope {scope} nested under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a nested scope resource's session effect: write questions: - How do I upload a file into a session for the backing resource of a scope nested under a requested role? - Can I push an external access data file for a nested scope under a request's role? instructions: - text: Upload a file into session {session} on nested scope {scope}'s backing resource, role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Push a data file to upload session {session} for scope {scope} nested under role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a nested scope's backing resource effect: read questions: - What's the number of upload sessions on the backing resource of a scope nested under a requested role? - Is there a count endpoint for upload sessions of a nested scope under a request's role? instructions: - text: Count upload sessions on nested scope {scope}'s backing resource under role {role}, request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Return the upload session total for scope {scope} nested under role {role} in request {req}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a requested role's home resource effect: read questions: - How many scopes does the home resource of a requested resource's role expose? - Is there a quick scope count for the resource a request's role belongs to? instructions: - text: Count scopes on role {role}'s home resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Return the scope total exposed by the home resource of role {role}, request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a requested role's home resource effect: read questions: - Which upload sessions were opened on the home resource of a requested resource's role? - Can I see external access data uploads for the resource a request's role belongs to? instructions: - text: List upload sessions on role {role}'s home resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show external data upload sessions for the home resource of role {role}, request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a requested role's home resource effect: write questions: - How do I open an upload session on the home resource of a requested resource's role? - Can I tag a new upload session on a request role's home resource with a reference ID? instructions: - text: Start an upload session on role {role}'s home resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Open an upload session tagged {refid} on the home resource of role {role}, request {req}. slots: refid: requestBody.referenceId role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a requested role's home resource effect: read questions: - What state is one upload session in on the home resource of a requested resource's role? - Has an upload session on a request role's home resource finished uploading? instructions: - text: Get upload session {session} on role {role}'s home resource in resource request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Check if upload session {session} is complete on the home resource of role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a requested role's home resource effect: destructive questions: - Can I delete an upload session on the home resource of a requested resource's role? - What discards one external data upload session on a request role's home resource? instructions: - text: Delete upload session {session} from role {role}'s home resource in resource request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Discard upload session {session} on the home resource of role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a requested role's home resource effect: write questions: - How do I mark an upload session done on the home resource of a requested resource's role? - Can I set the status on an upload session for a request role's home resource? instructions: - text: Mark upload session {session} as done ({done}) on role {role}'s home resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Set status {status} on upload session {session} for the home resource of role {role}, request {req}. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a requested role resource's upload session effect: read questions: - Which files sit in an upload session on the home resource of a requested resource's role? - Can I list files uploaded in one session on a request role's home resource? instructions: - text: List files in upload session {session} on role {role}'s home resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show uploaded files of session {session} for the home resource of role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a requested role resource's upload session effect: read questions: - What metadata is stored for a file uploaded to the home resource of a requested resource's role? - Can I look up a single file record in a session on a request role's home resource? instructions: - text: Get file record {file} from upload session {session}, role {role}'s home resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Show metadata for file {file} from session {session}, home resource of role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a requested role resource's session effect: read questions: - How do I download the bytes of a file uploaded to a requested role's home resource? - Can I read the raw media of a file in a session on a request role's home resource? instructions: - text: Download the stored bytes of file {file}, session {session}, role {role}'s home resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Fetch raw media of file {file} from session {session} on the home resource of role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a requested role resource's session effect: write questions: - What call swaps in new content for a file uploaded to a requested role's home resource? - Can I overwrite a file's media in an upload session on a request role's home resource? instructions: - text: Replace file {file}'s content with new bytes in session {session}, role {role}'s home resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Overwrite media content of file {file} in session {session} for the home resource of role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear file content in a requested role resource's session effect: destructive questions: - Can I wipe a file's bytes but keep the upload session on a requested role's home resource? - What deletes the media content of a file uploaded to a request role's home resource? instructions: - text: Wipe out file {file}'s content but keep session {session}, role {role}'s home resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Erase the media of file {file} from session {session} on the home resource of role {role}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a requested role resource's upload session effect: read questions: - How many files does one upload session hold on a requested role's home resource? - Is there a file count for an upload session on a request role's home resource? instructions: - text: Tell me how many files session {session} holds on role {role}'s home resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Return the file total of upload session {session}, home resource of role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a requested role resource's session effect: write questions: - How do I upload a file into a session on the home resource of a requested resource's role? - Can I push an external access data file to a request role's home resource? instructions: - text: Upload a file into session {session} on role {role}'s home resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Push a data file to upload session {session} for the home resource of role {role}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a requested role's home resource effect: read questions: - What's the number of upload sessions on the home resource of a requested resource's role? - Is there a count endpoint for upload sessions on a request role's home resource? instructions: - text: Count upload sessions on role {role}'s home resource in resource request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id - text: Return the upload session total for the home resource of role {role}, request {req}. slots: role: path.accessPackageResourceRole-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a request's requested resource effect: read questions: - How many roles does the requested resource of a resource request offer? - Is there a quick role count for the resource an access package request targets? instructions: - text: Count roles offered by the requested resource in resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Return the role total for the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a request's requested resource effect: read questions: - What scopes does the requested resource of a resource request expose? - Can I list the scopes on the resource an access package request targets, without going through roles? instructions: - text: List scopes exposed by the requested resource in resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show all scopes on the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a request's requested resource effect: write questions: - How do I define a new scope, root or not, on the requested resource of a resource request? - Can I give an origin ID when creating a scope on a request's requested resource? instructions: - text: Create scope {name} on the requested resource of resource request {req}. slots: name: requestBody.displayName req: path.accessPackageResourceRequest-id - text: Define a new scope with origin ID {origin} on the resource that request {req} is for. slots: origin: requestBody.originId req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get one scope of a request's requested resource effect: read questions: - What details does a single scope on a resource request's requested resource have? - Is a given scope on the resource an access package request targets the root scope? instructions: - text: Get scope {scope} of the requested resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Check whether scope {scope} on the resource that request {req} is for is root. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope from a request's requested resource effect: destructive questions: - Can I delete one scope from the requested resource of a resource request? - What removes a single scope exposed by the resource an access package request targets? instructions: - text: Delete scope {scope} from the requested resource of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Drop scope {scope} exposed by the resource that request {req} is for. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a request's requested resource effect: write questions: - Can I retitle a scope exposed by the requested resource of a resource request? - Which call edits the description of a scope exposed by the resource a request targets? instructions: - text: Rename scope {scope} on the requested resource of request {req} to {name}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on scope {scope} of the resource that request {req} is for. slots: desc: requestBody.description scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the backing resource of a requested resource's scope effect: read questions: - Which resource backs a given scope of a resource request's requested resource? - Can I read the backing resource behind a requested resource's scope? instructions: - text: Get the backing resource of scope {scope} on the requested resource of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show which resource backs scope {scope} in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the backing resource of a requested resource's scope effect: destructive questions: - Can I delete the backing resource reference on a scope of a request's requested resource? - What removes the resource link behind a requested resource's scope? instructions: - text: Delete the backing resource link of scope {scope} in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Detach scope {scope}'s backing resource on the requested resource of request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the backing resource of a requested resource's scope effect: write questions: - How do I rename the backing resource of a scope on a request's requested resource? - Can I edit the description of the resource behind a requested resource's scope? instructions: - text: Rename scope {scope}'s backing resource in resource request {req} to {name}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on the backing resource of scope {scope}, request {req}. slots: desc: requestBody.description scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a requested scope's backing resource effect: read questions: - Which environment hosts the backing resource of a scope on a request's requested resource? - Can I get environment details for the resource behind a requested resource's scope? instructions: - text: Get the environment of scope {scope}'s backing resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show which environment hosts the backing resource of scope {scope}, request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the backing resource of a requested resource's scope effect: write questions: - Is there a refresh action for the backing resource of a requested resource's scope? - Can I trigger refresh on the resource behind a scope of a resource request? instructions: - text: Refresh scope {scope}'s backing resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Run refresh on the backing resource of scope {scope} for request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a requested scope's backing resource effect: read questions: - What roles does the backing resource of a requested resource's scope offer? - Can I list roles on the resource behind a resource request scope? instructions: - text: List roles on scope {scope}'s backing resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show all roles offered by the backing resource of scope {scope}, request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a requested scope's backing resource effect: write questions: - How do I add a new role, with its type, to the backing resource of a requested resource's scope? - Can I set an origin system when creating a role on the resource behind a request's scope? instructions: - text: Create role {name} on scope {scope}'s backing resource in resource request {req}. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Add a new role of type {rtype} to the backing resource of scope {scope}, request {req}. slots: rtype: requestBody.type scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get one role of a requested scope's backing resource effect: read questions: - Which fields come back for one role offered by a requested scope's backing resource? - Which origin ID does a particular role on the resource behind a request's scope carry? instructions: - text: Get role {role} on scope {scope}'s backing resource in resource request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show details for role {role} offered by the backing resource of scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role from a requested scope's backing resource effect: destructive questions: - Is it possible to remove one role offered by a requested scope's backing resource? - What removes a single role offered by the resource behind a request's scope? instructions: - text: Delete role {role} from scope {scope}'s backing resource in resource request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Remove role {role} offered by the backing resource of scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a requested scope's backing resource effect: write questions: - Can I rename a role on the backing resource of a requested resource's scope? - What changes the description of one role on the resource behind a request's scope? instructions: - text: Rename role {role} on scope {scope}'s backing resource in request {req} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Change role {role}'s description to {desc}, backing resource of scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id desc: requestBody.description scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the home resource of a role listed on a requested scope effect: read questions: - Which resource is home to a role listed on a scope of a request's requested resource? - Can I read the home resource for a listed role on a requested resource's scope? instructions: - text: Get the home resource of listed role {role} on scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show which resource listed role {role} belongs to, from scope {scope} of resource request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the home resource of a role listed on a scope effect: destructive questions: - Can I delete the home resource link for a listed role on a requested resource's scope? - What detaches the belongs-to resource of a role listed on a request's scope? instructions: - text: Delete the home resource link of listed role {role} on scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Detach the resource that listed role {role} belongs to, from scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the home resource of a role listed on a scope effect: write questions: - How do I rename the home resource of a listed role on a requested resource's scope? - Can I edit the description of the home resource for a role listed on a request's scope? instructions: - text: Rename the home resource of listed role {role} on scope {scope}, request {req} to {name}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id name: requestBody.displayName - text: Set description {desc} on listed role {role}'s home resource from scope {scope}, request {req}. slots: desc: requestBody.description role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a listed role's home resource effect: read questions: - Which environment hosts the home resource of a role listed on a requested scope? - Can I get environment info for a listed role's home resource on a request's scope? instructions: - text: Get the environment of listed role {role}'s home resource on scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show which environment hosts the home of listed role {role}, from scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the home resource of a role listed on a scope effect: write questions: - Is there a refresh action for the home resource of a role listed on a requested scope? - Can I trigger refresh on a listed role's home resource from a request's scope? instructions: - text: Refresh the home resource of listed role {role} on scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Run refresh on listed role {role}'s home, from scope {scope} of request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a listed role's home resource effect: read questions: - Which upload sessions exist on the home resource of a role listed on a requested scope? - Can I list external access data uploads for a listed role's home resource on a scope? instructions: - text: List upload sessions on listed role {role}'s home resource, scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show external data upload sessions for the home of listed role {role} from scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a listed role's home resource effect: write questions: - How do I open an upload session for the home resource of a role listed on a requested scope? - Can I tag a new upload session for a listed role's home, from a scope, with a reference ID? instructions: - text: Start an upload session on listed role {role}'s home resource, scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Open an upload session tagged {refid} for the home of listed role {role} from scope {scope}, request {req}. slots: refid: requestBody.referenceId role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a listed role's home resource effect: read questions: - What state is one upload session in for a listed role's home resource on a requested scope? - Has an upload session for the home of a role listed on a scope finished uploading? instructions: - text: Get upload session {session} on listed role {role}'s home resource, scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Check if upload session {session} is complete for the home of listed role {role}, from scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a listed role's home resource effect: destructive questions: - Can I delete an upload session on the home resource of a role listed on a requested scope? - What discards one external data upload session for a listed role's home from a request's scope? instructions: - text: Delete upload session {session} from listed role {role}'s home resource, scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Discard upload session {session} for the home of listed role {role} from scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a listed role's home resource effect: write questions: - How do I mark an upload session as done for a listed role's home resource on a requested scope? - Can I set the status on an upload session for the home of a role listed on a request's scope? instructions: - text: Mark upload session {session} as done ({done}) on listed role {role}'s home, from scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Set status {status} on upload session {session} for listed role {role}'s home resource, scope {scope}, request {req}. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a listed role resource's upload session effect: read questions: - Which files sit in an upload session on the home resource of a role listed on a requested scope? - Can I list files uploaded in one session for a listed role's home from a request's scope? instructions: - text: List files in upload session {session} on listed role {role}'s home, from scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show uploaded files of session {session} for listed role {role}'s home resource, scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a listed role resource's upload session effect: read questions: - What metadata is stored for one file uploaded to a listed role's home resource on a requested scope? - Can I look up a single file record in a session for the home of a role listed on a scope? instructions: - text: Get file record {file} from session {session}, listed role {role}'s home, from scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show metadata for file {file} in session {session} of listed role {role}'s home resource, scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a listed role resource's session effect: read questions: - How do I download the bytes of a file uploaded to a listed role's home resource on a requested scope? - Can I read the raw media of a file in a session for the home of a role listed on a request's scope? instructions: - text: Download the stored bytes of file {file}, session {session}, listed role {role}'s home, from scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Fetch raw media of file {file} from session {session} of listed role {role}'s home resource, scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a listed role resource's session effect: write questions: - What call swaps in new content for a file uploaded to a listed role's home resource on a scope? - Can I overwrite a file's media in an upload session for the home of a role listed on a request's scope? instructions: - text: Replace file {file}'s content with new bytes in session {session}, listed role {role}'s home, from scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Overwrite media content of file {file} in session {session} for listed role {role}'s home resource, scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear file content in a listed role resource's session effect: destructive questions: - Can I wipe a file's bytes but keep the upload session for a listed role's home resource on a scope? - What deletes the media content of a file uploaded for the home of a role listed on a request's scope? instructions: - text: Wipe out file {file}'s content but keep session {session}, listed role {role}'s home, from scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Erase the media of file {file} from session {session} for listed role {role}'s home resource, scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a listed role resource's upload session effect: read questions: - How many files does one upload session hold for a listed role's home resource on a requested scope? - Is there a file count for an upload session on the home of a role listed on a request's scope? instructions: - text: Tell me how many files session {session} holds for listed role {role}'s home, from scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the file total of upload session {session}, listed role {role}'s home resource, scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a listed role resource's session effect: write questions: - How do I upload a file into a session for the home resource of a role listed on a requested scope? - Can I push an external access data file for a listed role's home from a request's scope? instructions: - text: Upload a file into session {session} on listed role {role}'s home resource, scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Push a data file to upload session {session} for listed role {role}'s home, from scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a listed role's home resource effect: read questions: - How many upload sessions exist for the home of a role listed on a requested scope? - Is there a count endpoint for upload sessions of a listed role's home from a request's scope? instructions: - text: Count upload sessions on listed role {role}'s home resource, scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the upload session total for listed role {role}'s home, from scope {scope}, request {req}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a requested scope's backing resource effect: read questions: - How many roles does the backing resource of a requested resource's scope offer? - Is there a quick role count for the resource behind a request's scope? instructions: - text: Count roles on scope {scope}'s backing resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the role total offered by the backing resource of scope {scope}, request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a requested scope's backing resource effect: read questions: - Which upload sessions were opened on the backing resource of a requested resource's scope? - Can I see external access data uploads for the resource behind a request's scope? instructions: - text: List upload sessions on scope {scope}'s backing resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show external data upload sessions for the backing resource of scope {scope}, request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a scope's backing resource effect: write questions: - How do I open an upload session on the backing resource of a requested resource's scope? - Can I tag a new upload session on a request scope's backing resource with a reference ID? instructions: - text: Start an upload session on scope {scope}'s backing resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Open an upload session tagged {refid} on the backing resource of scope {scope}, request {req}. slots: refid: requestBody.referenceId scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a scope's backing resource effect: read questions: - What state is one upload session in on the backing resource of a requested resource's scope? - Has an upload session on a request scope's backing resource finished uploading? instructions: - text: Get upload session {session} on scope {scope}'s backing resource in resource request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Check if upload session {session} is complete on the backing resource of scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a scope's backing resource effect: destructive questions: - Can I delete an upload session on the backing resource of a requested resource's scope? - What discards one external data upload session on a request scope's backing resource? instructions: - text: Delete upload session {session} from scope {scope}'s backing resource in resource request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Discard upload session {session} on the backing resource of scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a scope's backing resource effect: write questions: - How do I mark an upload session done on the backing resource of a requested resource's scope? - Can I set the status on an upload session for a request scope's backing resource? instructions: - text: Mark upload session {session} as done ({done}) on scope {scope}'s backing resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Set status {status} on upload session {session} for the backing resource of scope {scope}, request {req}. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a requested scope resource's upload session effect: read questions: - Which files sit in an upload session on the backing resource of a requested resource's scope? - Can I list files uploaded in one session on a request scope's backing resource? instructions: - text: List files in upload session {session} on scope {scope}'s backing resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show uploaded files of session {session} for the backing resource of scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a requested scope resource's upload session effect: read questions: - What metadata is stored for a file uploaded to the backing resource of a requested resource's scope? - Can I look up a single file record in a session on a request scope's backing resource? instructions: - text: Get file record {file} from upload session {session}, scope {scope}'s backing resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Show metadata for file {file} from session {session}, backing resource of scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a requested scope resource's session effect: read questions: - How do I download the bytes of a file uploaded to a requested scope's backing resource? - Can I read the raw media of a file in a session on a request scope's backing resource? instructions: - text: Download the stored bytes of file {file}, session {session}, scope {scope}'s backing resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Fetch raw media of file {file} from session {session} on the backing resource of scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a requested scope resource's session effect: write questions: - What call swaps in new content for a file uploaded to a requested scope's backing resource? - Can I overwrite a file's media in an upload session on a request scope's backing resource? instructions: - text: Replace file {file}'s content with new bytes in session {session}, scope {scope}'s backing resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Overwrite media content of file {file} in session {session} for the backing resource of scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear file content in a requested scope resource's session effect: destructive questions: - Can I wipe a file's bytes but keep the upload session on a requested scope's backing resource? - What deletes the media content of a file uploaded to a request scope's backing resource? instructions: - text: Wipe out file {file}'s content but keep session {session}, scope {scope}'s backing resource, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Erase the media of file {file} from session {session} on the backing resource of scope {scope}, request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a requested scope resource's upload session effect: read questions: - How many files does one upload session hold on a requested scope's backing resource? - Is there a file count for an upload session on a request scope's backing resource? instructions: - text: Tell me how many files session {session} holds on scope {scope}'s backing resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the file total of upload session {session}, backing resource of scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a requested scope resource's session effect: write questions: - How do I upload a file into a session on the backing resource of a requested resource's scope? - Can I push an external access data file to a request scope's backing resource? instructions: - text: Upload a file into session {session} on scope {scope}'s backing resource, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Push a data file to upload session {session} for the backing resource of scope {scope}, request {req}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a scope's backing resource effect: read questions: - What's the number of upload sessions on the backing resource of a requested resource's scope? - Is there a count endpoint for upload sessions on a request scope's backing resource? instructions: - text: Count upload sessions on scope {scope}'s backing resource in resource request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id - text: Return the upload session total for the backing resource of scope {scope}, request {req}. slots: scope: path.accessPackageResourceScope-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a request's requested resource effect: read questions: - How many scopes does the requested resource of a resource request expose? - Can I fetch only the number of scopes exposed by the resource an access package request targets? instructions: - text: Count scopes exposed by the requested resource in resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Return the scope total for the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a request's requested resource effect: read questions: - Which upload sessions were opened on the requested resource of a resource request? - Can I see external access data uploads made to the resource an access package request targets? instructions: - text: List upload sessions on the requested resource of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Show external data upload sessions for the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a request's requested resource effect: write questions: - How do I open an upload session on the requested resource of a resource request? - Can I tag a new upload session on a request's requested resource with an access review reference ID? instructions: - text: Start an upload session on the requested resource of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Open an upload session tagged {refid} for the resource that request {req} is for. slots: refid: requestBody.referenceId req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a request's requested resource effect: read questions: - What state is one upload session in on the requested resource of a resource request? - Has an upload session on the resource an access package request targets finished uploading? instructions: - text: Get upload session {session} on the requested resource of resource request {req}. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Check if upload session {session} is complete for the resource that request {req} is for. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a request's requested resource effect: destructive questions: - Can I delete an upload session on the requested resource of a resource request? - What discards one external data upload session on the resource an access package request targets? instructions: - text: Delete upload session {session} from the requested resource of resource request {req}. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Discard upload session {session} for the resource that request {req} is for. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a request's requested resource effect: write questions: - How do I mark an upload session done on the requested resource of a resource request? - Can I set the status on an upload session for the resource an access package request targets? instructions: - text: Mark upload session {session} as done ({done}) on the requested resource of request {req}. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone req: path.accessPackageResourceRequest-id - text: Set status {status} on upload session {session} for the resource that request {req} is for. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a requested resource's upload session effect: read questions: - Which files sit in an upload session on the requested resource of a resource request? - Can I list files uploaded in one session for the resource an access package request targets? instructions: - text: List files in upload session {session} on the requested resource of request {req}. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Show uploaded files of session {session} for the resource that request {req} is for. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a requested resource's upload session effect: read questions: - What metadata is stored for a file uploaded to the requested resource of a resource request? - Can I look up a single file record in a session for the resource an access package request targets? instructions: - text: Get file {file} in upload session {session} on the requested resource of request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Show metadata for file {file} from session {session}, resource that request {req} is for. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file from a requested resource's upload session effect: read questions: - How do I download the bytes of a file uploaded to the requested resource of a resource request? - Can I read the raw media of a file in a session for the resource an access package request targets? instructions: - text: Download the stored bytes of file {file}, session {session}, requested resource of request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Fetch raw media of file {file} from session {session} for the resource that request {req} is for. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a requested resource's session effect: write questions: - What call swaps in new content for a file uploaded to the requested resource of a resource request? - Can I overwrite a file's media in an upload session for the resource an access package request targets? instructions: - text: Replace file {file}'s content with new bytes in session {session}, requested resource of request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Overwrite media content of file {file} in session {session} for the resource that request {req} is for. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Clear file content in a requested resource's upload session effect: destructive questions: - Can I wipe a file's bytes but keep the upload session on the requested resource of a resource request? - What deletes the media content of a file uploaded for the resource an access package request targets? instructions: - text: Wipe out file {file}'s content but keep session {session}, requested resource of request {req}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Erase the media of file {file} from session {session} for the resource that request {req} is for. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a requested resource's upload session effect: read questions: - How many files does one upload session hold on the requested resource of a resource request? - Is there a file count for an upload session on the resource an access package request targets? instructions: - text: Tell me how many files session {session} holds on the requested resource of request {req}. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Return the file total of upload session {session} for the resource that request {req} is for. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a requested resource's upload session effect: write questions: - How do I upload a file into a session on the requested resource of a resource request? - Can I push an external access data file to the resource an access package request targets? instructions: - text: Upload a file into session {session} on the requested resource of request {req}. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id - text: Push a data file to upload session {session} for the resource that request {req} is for. slots: session: path.customDataProvidedResourceUploadSession-id req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/{accessPackageResourceRequest-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions of a request's requested resource effect: read questions: - What's the number of upload sessions on the requested resource of a resource request? - Is there a count endpoint for upload sessions on the resource an access package request targets? instructions: - text: Count upload sessions on the requested resource of resource request {req}. slots: req: path.accessPackageResourceRequest-id - text: Return the upload session total for the resource that request {req} is for. slots: req: path.accessPackageResourceRequest-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRequests/$count'].get update: x-apievangelist-phrasing: intent: Count access package resource requests effect: read questions: - How many access package resource requests exist in entitlement management? - Can I get just the total number of resource requests without listing them? instructions: - text: Count all access package resource requests. - text: Return the total number of resource requests in entitlement management. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes'].get update: x-apievangelist-phrasing: intent: List resource role scopes in entitlement management effect: read questions: - Which resource role scopes are defined in entitlement management? - Can I filter or page through the role-and-scope pairings used by access packages? instructions: - text: List all resource role scopes. - text: Show the first {top} resource role scopes. slots: top: query.$top method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes'].post update: x-apievangelist-phrasing: intent: Create a resource role scope effect: write questions: - How do I pair a resource role with a resource scope in entitlement management? - What does it take to create a new resource role scope entry? instructions: - text: Create a resource role scope that pairs a resource role with a resource scope. - text: Add a new role scope entry linking a role to a scope. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}'].get update: x-apievangelist-phrasing: intent: Get a resource role scope effect: read questions: - What does a single resource role scope contain, and when was it created? - Can I look up one role scope entry by its ID? instructions: - text: Get resource role scope {rs}. slots: rs: path.accessPackageResourceRoleScope-id - text: Show the created date of role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a resource role scope effect: destructive questions: - Can I delete a resource role scope I no longer need? - What happens when a role scope entry is removed from entitlement management? instructions: - text: Delete resource role scope {rs}. slots: rs: path.accessPackageResourceRoleScope-id - text: Remove the role scope entry {rs} permanently. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a resource role scope effect: write questions: - How do I change which role or scope a resource role scope points to? - Can I edit an existing role scope entry in place? instructions: - text: Update resource role scope {rs} with a different role or scope. slots: rs: path.accessPackageResourceRoleScope-id - text: Patch role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role'].get update: x-apievangelist-phrasing: intent: Get the role in a resource role scope effect: read questions: - Which resource role does a given role scope entry reference? - Can I read the role half of a resource role scope pairing? instructions: - text: Get the role referenced by role scope {rs}. slots: rs: path.accessPackageResourceRoleScope-id - text: Show the display name and origin of the role in role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role'].delete update: x-apievangelist-phrasing: intent: Remove the role from a resource role scope effect: destructive questions: - Can I delete the role reference from a resource role scope pairing? - What unlinks the role half of a role scope entry? instructions: - text: Delete the role link on role scope {rs}. slots: rs: path.accessPackageResourceRoleScope-id - text: Unlink the role from role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role'].patch update: x-apievangelist-phrasing: intent: Update the role in a resource role scope effect: write questions: - How do I rename the role referenced by a resource role scope? - Can I change the type or description of the role in a role scope pairing? instructions: - text: Rename the role in role scope {rs} to {name}. slots: rs: path.accessPackageResourceRoleScope-id name: requestBody.displayName - text: Set the role type to {rtype} for role scope entry {rs}. slots: rtype: requestBody.type rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource'].get update: x-apievangelist-phrasing: intent: Get the resource behind a role scope's role effect: read questions: - Which resource does the role in a resource role scope belong to? - Can I read the owning resource of a role scope pairing's role? instructions: - text: Get the resource that role scope {rs}'s role belongs to. slots: rs: path.accessPackageResourceRoleScope-id - text: Show the owning resource of the role paired in role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a role scope's role effect: destructive questions: - Can I delete the resource reference on the role of a resource role scope? - What detaches the owning resource from a role scope pairing's role? instructions: - text: Delete the resource link on role scope {rs}'s role. slots: rs: path.accessPackageResourceRoleScope-id - text: Detach the owning resource from the role paired in role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource of a role scope's role effect: write questions: - How do I rename the resource that a role scope's role belongs to? - Can I change the requestor attributes on the owning resource of a role scope pairing's role? instructions: - text: Rename the resource of role scope {rs}'s role to {name}. slots: rs: path.accessPackageResourceRoleScope-id name: requestBody.displayName - text: Set description {desc} on the owning resource of the role in role scope entry {rs}. slots: desc: requestBody.description rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a role scope role's resource effect: read questions: - Which environment hosts the resource behind a resource role scope's role? - Can I get environment details for the owning resource in a role scope pairing? instructions: - text: Get the environment of the resource behind role scope {rs}'s role. slots: rs: path.accessPackageResourceRoleScope-id - text: Show which environment hosts the owning resource for role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource of a role scope's role effect: write questions: - Is there a refresh action for the resource behind a resource role scope's role? - Can I trigger refresh on the owning resource of a role scope pairing? instructions: - text: Refresh the resource behind role scope {rs}'s role. slots: rs: path.accessPackageResourceRoleScope-id - text: Run the refresh action on the owning resource for role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a role scope role's resource effect: read questions: - What roles does the resource behind a resource role scope's role offer? - Can I see every sibling role on the owning resource of a role scope pairing? instructions: - text: List roles offered by the resource behind role scope {rs}'s role. slots: rs: path.accessPackageResourceRoleScope-id - text: Show all roles on the owning resource for role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a role scope role's resource effect: write questions: - How do I add a new role to the resource behind a resource role scope's role? - Can I set an origin ID when creating a role on a role scope pairing's owning resource? instructions: - text: Create role {name} on the resource behind role scope {rs}'s role. slots: name: requestBody.displayName rs: path.accessPackageResourceRoleScope-id - text: Add a new role with origin ID {origin} to the owning resource for role scope entry {rs}. slots: origin: requestBody.originId rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get one role of a role scope role's resource effect: read questions: - What details does one role on a resource role scope's owning resource have? - Which origin system does a specific role on a role scope pairing's resource come from? instructions: - text: Get role {role} on the resource behind role scope {rs}'s role. slots: role: path.accessPackageResourceRole-id rs: path.accessPackageResourceRoleScope-id - text: Show origin system and type of role {role} on the owning resource for role scope entry {rs}. slots: role: path.accessPackageResourceRole-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role from a role scope role's resource effect: destructive questions: - Can I delete one role from the resource behind a resource role scope's role? - What removes a single role from the owning resource of a role scope pairing? instructions: - text: Delete role {role} from the resource behind role scope {rs}'s role. slots: role: path.accessPackageResourceRole-id rs: path.accessPackageResourceRoleScope-id - text: Remove role {role} on the owning resource for role scope entry {rs}. slots: role: path.accessPackageResourceRole-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a role scope role's resource effect: write questions: - Can I rename a role on the resource behind a resource role scope's role? - What changes the description of one role on a role scope pairing's owning resource? instructions: - text: Rename role {role} on the resource behind role scope {rs}'s role to {name}. slots: role: path.accessPackageResourceRole-id rs: path.accessPackageResourceRoleScope-id name: requestBody.displayName - text: Change role {role}'s description to {desc} on the owning resource for role scope entry {rs}. slots: role: path.accessPackageResourceRole-id desc: requestBody.description rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a role scope role's resource effect: read questions: - How many roles does the resource behind a resource role scope's role offer? - Is there a quick role count for a role scope pairing's owning resource? instructions: - text: Count roles offered by the resource behind role scope {rs}'s role. slots: rs: path.accessPackageResourceRoleScope-id - text: Return the role total on the owning resource for role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a role scope role's resource effect: read questions: - What scopes does the resource behind a resource role scope's role expose? - Can I list the scopes on a role scope pairing's owning resource? instructions: - text: List scopes exposed by the resource behind role scope {rs}'s role. slots: rs: path.accessPackageResourceRoleScope-id - text: Show all scopes on the owning resource for role scope entry {rs}. slots: rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a role scope role's resource effect: write questions: - How do I define a new scope, root or not, on the resource behind a role scope's role? - Can I give an origin system when creating a scope on a role scope pairing's owning resource? instructions: - text: Define new scope {name} on the owning resource of role scope {rs}'s paired role. slots: name: requestBody.displayName rs: path.accessPackageResourceRoleScope-id - text: Define a new scope with isRootScope {root} on the owning resource for role scope entry {rs}. slots: root: requestBody.isRootScope rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get one scope of a role scope role's resource effect: read questions: - What details does a single scope on a resource role scope's owning resource have? - Is a given scope on a role scope pairing's resource marked as the root scope? instructions: - text: Fetch details of scope {scope} exposed by role scope {rs}'s paired role resource. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Check whether scope {scope} on the owning resource for role scope entry {rs} is root. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope from a role scope role's resource effect: destructive questions: - Is it possible to drop a single scope exposed by a role scope pairing's resource? - What removes a single scope from a role scope pairing's owning resource? instructions: - text: Drop scope {scope} exposed by the resource of role scope {rs}'s paired role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Remove exposed scope {scope} from the owning resource in role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a role scope role's resource effect: write questions: - Can I retitle a scope on the resource behind a resource role scope's role? - What changes the origin ID of one scope on a role scope pairing's owning resource? instructions: - text: Retitle exposed scope {scope} to {name} on role scope {rs}'s paired role resource. slots: scope: path.accessPackageResourceScope-id name: requestBody.displayName rs: path.accessPackageResourceRoleScope-id - text: Set origin ID {origin} on scope {scope} of the owning resource for role scope entry {rs}. slots: origin: requestBody.originId scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource behind a scope via a role scope effect: read questions: - Which resource sits behind a scope on the owning resource of a role scope pairing? - Can I read the scope-level resource reached through a resource role scope's role? instructions: - text: Get the resource behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Show the scope-level resource for scope {scope} under role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource behind a scope via a role scope effect: destructive questions: - Can I delete the resource link on a scope reached through a resource role scope's role? - What detaches the scope-level resource under a role scope pairing? instructions: - text: Delete the resource link behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Detach the scope-level resource of scope {scope} under role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource behind a scope via a role scope effect: write questions: - How do I rename the resource behind a scope reached through a resource role scope? - Can I edit the description of the scope-level resource under a role scope pairing? instructions: - text: Rename the resource behind scope {scope}, reached via role scope {rs}'s role, to {name}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id name: requestBody.displayName - text: Set description {desc} on the scope-level resource of scope {scope} under role scope entry {rs}. slots: desc: requestBody.description scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get a role scope's scope-level resource environment effect: read questions: - Which environment hosts the resource behind a scope reached through a resource role scope? - Can I get environment info for the scope-level resource under a role scope pairing? instructions: - text: Get the environment of the resource behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Show which environment hosts the scope-level resource of scope {scope}, role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource behind a scope via a role scope effect: write questions: - Is there a refresh action for the resource behind a scope reached through a role scope? - Can I trigger refresh on the scope-level resource under a role scope pairing? instructions: - text: Refresh the resource behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Run the refresh action on the scope-level resource of scope {scope}, role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles of a scope-level resource via a role scope effect: read questions: - What roles does the resource behind a scope reached through a role scope offer? - Can I list roles on the scope-level resource under a role scope pairing? instructions: - text: List roles on the resource behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Show all roles offered by the scope-level resource of scope {scope}, role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a scope-level resource via a role scope effect: write questions: - How do I add a new role to the resource behind a scope reached through a role scope? - Can I set a role type when creating a role on the scope-level resource of a role scope pairing? instructions: - text: Create role {name} on the resource behind scope {scope}, reached via role scope {rs}'s role. slots: name: requestBody.displayName scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Add a new role of type {rtype} to the scope-level resource of scope {scope}, role scope entry {rs}. slots: rtype: requestBody.type scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get one role of a scope-level resource via a role scope effect: read questions: - What details does one role on the resource behind a scope reached through a role scope have? - Which origin ID does a particular role on a role scope pairing's scope-level resource carry? instructions: - text: Fetch details of role {role} offered at scope {scope} through role scope {rs}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Show details for role {role} on the scope-level resource of scope {scope}, role scope entry {rs}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role from a scope-level resource via a role scope effect: destructive questions: - Can I delete one role from the resource behind a scope reached through a role scope? - What removes a single role from the scope-level resource under a role scope pairing? instructions: - text: Delete role {role} from the resource behind scope {scope}, reached via role scope {rs}'s role. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Remove role {role} on the scope-level resource of scope {scope}, role scope entry {rs}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a scope-level resource via a role scope effect: write questions: - Can I rename a role on the resource behind a scope reached through a role scope? - Which call edits a role's description on the scope-level resource under a role scope? instructions: - text: Retitle role {role} as {name} at scope {scope} through role scope {rs}. slots: role: path.accessPackageResourceRole-id name: requestBody.displayName scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Change role {role}'s description to {desc} on the scope-level resource of scope {scope}, role scope entry {rs}. slots: role: path.accessPackageResourceRole-id desc: requestBody.description scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a scope-level resource via a role scope effect: read questions: - How many roles does the resource behind a scope reached through a role scope offer? - Is there a quick role count for the scope-level resource under a role scope pairing? instructions: - text: Count roles on the resource behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Return the role total of the scope-level resource of scope {scope}, role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions of a role scope's scope-level resource effect: read questions: - Which upload sessions exist on the resource behind a scope reached through a role scope? - Can I see external access data uploads for the scope-level resource under a role scope pairing? instructions: - text: List upload sessions on the resource behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Show external data upload sessions for the scope-level resource of scope {scope}, role scope entry {rs}. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Open an upload session on a role scope's scope resource effect: write questions: - How do I open an upload session on the resource behind a scope reached through a role scope? - Can I tag a new upload session on a role scope pairing's scope-level resource with a reference ID? instructions: - text: Start an upload session on the resource behind scope {scope}, reached via role scope {rs}'s role. slots: scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Open an upload session tagged {refid} on the scope-level resource of scope {scope}, role scope entry {rs}. slots: refid: requestBody.referenceId scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session of a role scope's scope resource effect: read questions: - What state is one upload session in on the resource behind a scope reached through a role scope? - Has an upload session on a role scope pairing's scope-level resource finished uploading? instructions: - text: Get upload session {session} on the resource behind scope {scope}, reached via role scope {rs}'s role. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Check if upload session {session} is complete on the scope-level resource of scope {scope}, role scope entry {rs}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session of a role scope's scope resource effect: destructive questions: - Can I delete an upload session on the resource behind a scope reached through a role scope? - What discards one external data upload session on a role scope pairing's scope-level resource? instructions: - text: Delete upload session {session} from the resource behind scope {scope}, reached via role scope {rs}'s role. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Discard upload session {session} on the scope-level resource of scope {scope}, role scope entry {rs}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session of a role scope's scope resource effect: write questions: - How do I mark an upload session done on the resource behind a scope reached through a role scope? - Can I set the status on an upload session for a role scope pairing's scope-level resource? instructions: - text: Mark upload session {session} as done ({done}) on the resource behind scope {scope}, via role scope {rs}'s role. slots: session: path.customDataProvidedResourceUploadSession-id done: requestBody.isUploadDone scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id - text: Set status {status} on upload session {session} for the scope-level resource of scope {scope}, role scope entry {rs}. slots: status: requestBody.status session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a nested-scope upload session effect: read questions: - Which files were uploaded to a session on the scope resource nested under a role-scope pairing's role? - Can I see every file in a custom-data upload session reached through a pairing's role and then a scope? instructions: - text: List files in session {session} under scope {scope} of the role resource of pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Show the first 10 uploaded files for session {session} on scope {scope}, reached via pairing {rrs}'s role. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file from a nested-scope upload session effect: read questions: - How can I read the details of a single file uploaded via a pairing's role, then one of its scopes? - What metadata does one uploaded file carry in a nested role-then-scope upload session? instructions: - text: Get file {file} from session {session} under scope {scope} of pairing {rrs}'s role resource. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Fetch metadata for uploaded file {file} in role-then-scope session {session}, pairing {rrs}, scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download a file's content from a nested-scope session effect: read questions: - Can I download the raw bytes of a file sitting in a pairing's role-then-scope upload session? - Where do I pull the actual media content of a custom data file uploaded through a pairing's role and scope? instructions: - text: Download the content of file {file} in session {session}, scope {scope}, via pairing {rrs}'s role. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Stream the raw bytes of role-path file {file} from session {session} on scope {scope} for pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace a file's content in a nested-scope session effect: write questions: - Can I overwrite the media content of a file already uploaded via a pairing's role, then scope? - How is the stored content of an uploaded file replaced inside a role-then-scope upload session? instructions: - text: Replace the content of file {file} in session {session} on scope {scope} of pairing {rrs}'s role. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Overwrite role-path uploaded file {file} bytes in session {session}, scope {scope}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete a file's content from a nested-scope session effect: destructive questions: - Can I wipe the stored bytes of a file in a pairing's role-then-scope upload session? - What removes the media content of one uploaded file on the nested scope resource under a pairing's role? instructions: - text: Delete the content of file {file} in session {session}, scope {scope}, under pairing {rrs}'s role. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Clear the stored bytes of role-path file {file} in upload session {session} on scope {scope}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a nested-scope upload session effect: read questions: - How many files have been uploaded to a session on a scope reached through a pairing's role? - Is there a quick file tally for a role-then-scope custom data upload session? instructions: - text: Count the files in session {session} on scope {scope} of pairing {rrs}'s role resource. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Give me the uploaded file total for role-path session {session}, scope {scope}, pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file into a nested-scope upload session effect: write questions: - How do I push a custom data file into an upload session reached via a pairing's role and a scope? - Can a file be added to an existing session on the nested scope resource of a pairing's role? instructions: - text: Upload a file into session {session} on scope {scope} of pairing {rrs}'s role resource. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Add a new custom data file to role-path upload session {session}, scope {scope}, pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a nested-scope resource effect: read questions: - How many upload sessions exist on the scope resource nested under a pairing's role? - Can I get a session tally for the resource reached via a pairing's role, then a scope? instructions: - text: Count upload sessions on scope {scope} under the role resource of pairing {rrs}. slots: scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Tell me how many custom data sessions live on role-path scope {scope} for pairing {rrs}. slots: scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes on a pairing's role resource effect: read questions: - How many scopes does the resource behind a role-scope pairing's role expose? - Can I count the scopes defined on the role's resource for one pairing? instructions: - text: Count the scopes on the role resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Tell me how many scopes the resource behind pairing {rrs}'s role has. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions on a pairing's role resource effect: read questions: - Which custom data upload sessions exist on the resource behind an access package pairing's role? - Can I filter upload sessions on a pairing's role resource by their reference ID? instructions: - text: List upload sessions on the role resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Show upload sessions behind pairing {rrs}'s role, newest first. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a pairing's role resource effect: write questions: - How do I open a custom data upload session on the resource behind a pairing's role? - Can a new upload session on a pairing's role resource be tied to an access review instance? instructions: - text: Create an upload session on the role resource of pairing {rrs} for reference {referenceId}. slots: rrs: path.accessPackageResourceRoleScope-id referenceId: requestBody.referenceId - text: Open a new custom data session behind pairing {rrs}'s role. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session on a pairing's role resource effect: read questions: - What status and stats does one upload session on a pairing's role resource report? - Can I check whether a single session behind a pairing's role has finished uploading? instructions: - text: Get upload session {session} on the role resource of pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Show status of role-resource session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session on a pairing's role resource effect: destructive questions: - Can I remove an upload session from the resource behind a pairing's role? - What happens if I delete a custom data session on a pairing's role resource? instructions: - text: Delete upload session {session} from the role resource of pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Remove role-resource custom data session {session} under pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session on a pairing's role resource effect: write questions: - How do I mark an upload session on a pairing's role resource as done? - Can I change the reference ID of a session behind a pairing's role? instructions: - text: 'Mark upload session {session} on pairing {rrs}''s role resource as done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on role-resource session {session} for pairing {rrs}. slots: referenceId: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a pairing's role-resource session effect: read questions: - Which files sit in an upload session on the resource behind a pairing's role? - Can I page through uploaded files in a role-resource session for one pairing? instructions: - text: List files in session {session} on the role resource of pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Show uploaded files in role-resource session {session}, pairing {rrs}, 20 at a time. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a pairing's role-resource session effect: read questions: - How can I look up one uploaded file in a session behind a pairing's role? - What details are stored for a single file in a role-resource upload session? instructions: - text: Get file {file} from session {session} on pairing {rrs}'s role resource. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Fetch file record {file} in role-resource session {session} of pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content from a role-resource session effect: read questions: - Can I download what was actually uploaded in a file behind a pairing's role resource session? - Where is the raw content of a role-resource session file served? instructions: - text: Download the content of file {file} in session {session} on pairing {rrs}'s role resource. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Pull raw bytes of role-resource file {file}, session {session}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a role-resource session effect: write questions: - How do I overwrite a file's bytes inside a session on a pairing's role resource? - Can I re-upload the content of an existing file behind a pairing's role? instructions: - text: Replace the content of file {file} in session {session} on pairing {rrs}'s role resource. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Overwrite role-resource file {file} bytes in session {session} for pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a role-resource session effect: destructive questions: - Can I clear the stored content of one file in a session behind a pairing's role? - What wipes the bytes of an uploaded role-resource file without touching the session? instructions: - text: Delete the content of file {file} in session {session} on pairing {rrs}'s role resource. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Wipe stored bytes of role-resource file {file} from session {session}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a pairing's role-resource session effect: read questions: - How many files are in an upload session behind a pairing's role? - Is there a count of uploaded files for one role-resource session? instructions: - text: Count files in session {session} on the role resource of pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Tally uploaded files in role-resource session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a pairing's role-resource session effect: write questions: - How do I upload a custom data file to a session on a pairing's role resource? - Can I add a file to an open session behind a pairing's role? instructions: - text: Upload a file into session {session} on the role resource of pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Send a custom data file to role-resource session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/role/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a pairing's role resource effect: read questions: - How many upload sessions are open on the resource behind a pairing's role? - Can I get the number of custom data sessions on one pairing's role resource? instructions: - text: Count upload sessions on the role resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Tell me the session total behind pairing {rrs}'s role. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope'].get update: x-apievangelist-phrasing: intent: Get the scope of a role-scope pairing effect: read questions: - Which resource scope is attached to a given access package role-scope pairing? - Can I see the display name and origin of the scope in one pairing? instructions: - text: Get the scope of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Show which scope pairing {rrs} grants its role on. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope'].delete update: x-apievangelist-phrasing: intent: Remove the scope from a role-scope pairing effect: destructive questions: - Can I delete the scope link from an access package role-scope pairing? - What happens when a pairing's scope navigation is removed? instructions: - text: Delete the scope of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Detach the scope from role-scope pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope'].patch update: x-apievangelist-phrasing: intent: Update the scope of a role-scope pairing effect: write questions: - How do I rename or re-describe the scope attached to a pairing? - Can I flag a pairing's scope as the root scope of its resource? instructions: - text: Rename the scope of pairing {rrs} to {displayName}. slots: rrs: path.accessPackageResourceRoleScope-id displayName: requestBody.displayName - text: Set isRootScope to {isRootScope} on the scope of pairing {rrs}. slots: isRootScope: requestBody.isRootScope rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource'].get update: x-apievangelist-phrasing: intent: Get the resource behind a pairing's scope effect: read questions: - Which catalog resource does a role-scope pairing's scope belong to? - Can I read the origin system and attributes of the resource attached to a pairing's scope? instructions: - text: Get the resource attached to the scope of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Show the scope-side resource details for pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource'].delete update: x-apievangelist-phrasing: intent: Remove the resource from a pairing's scope effect: destructive questions: - Can I delete the resource link attached to a pairing's scope? - What removes the scope-side resource navigation for one pairing? instructions: - text: Delete the resource attached to the scope of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Unlink the scope-side resource from pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource behind a pairing's scope effect: write questions: - How do I change the display name of the resource tied to a pairing's scope? - Can I edit the description of the scope-side resource for a pairing? instructions: - text: Rename the scope-side resource of pairing {rrs} to {displayName}. slots: rrs: path.accessPackageResourceRoleScope-id displayName: requestBody.displayName - text: Set description {description} on the resource attached to pairing {rrs}'s scope. slots: description: requestBody.description rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a pairing's scope resource effect: read questions: - Which environment hosts the resource attached to a pairing's scope? - Can I see environment details for the scope-side resource of one pairing? instructions: - text: Get the environment of the resource attached to pairing {rrs}'s scope. slots: rrs: path.accessPackageResourceRoleScope-id - text: Show where the scope-side resource of pairing {rrs} lives. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource behind a pairing's scope effect: write questions: - How do I trigger a refresh of the resource attached to a pairing's scope? - Can the scope-side resource of a pairing be refreshed on demand? instructions: - text: Refresh the resource attached to the scope of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Run a refresh on pairing {rrs}'s scope-side resource. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles on a pairing's scope resource effect: read questions: - Which roles does the resource attached to a pairing's scope offer? - Can I filter the roles of a pairing's scope-side resource by name? instructions: - text: List roles on the scope-side resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Show every role defined on the resource behind pairing {rrs}'s scope. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a pairing's scope resource effect: write questions: - How do I define a new role on the resource attached to a pairing's scope? - Can I give a new scope-side resource role an origin ID from the source system? instructions: - text: Create role {displayName} on the scope-side resource of pairing {rrs}. slots: displayName: requestBody.displayName rrs: path.accessPackageResourceRoleScope-id - text: Add a role with origin ID {originId} to pairing {rrs}'s scope-side resource. slots: originId: requestBody.originId rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role on a pairing's scope resource effect: read questions: - What does one role on the resource attached to a pairing's scope look like? - Can I read the origin system of a single scope-side resource role? instructions: - text: Get role {role} on the scope-side resource of pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show scope-side role {role} details for pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role on a pairing's scope resource effect: destructive questions: - Can I remove a role from the resource attached to a pairing's scope? - What deletes one scope-side resource role for a pairing? instructions: - text: Delete role {role} from the scope-side resource of pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Remove scope-side role {role} under pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a pairing's scope resource effect: write questions: - How do I rename a role on the resource attached to a pairing's scope? - Can I change the description of a scope-side resource role? instructions: - text: Rename role {role} on pairing {rrs}'s scope-side resource to {displayName}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id displayName: requestBody.displayName - text: Set description {description} on scope-side role {role} for pairing {rrs}. slots: description: requestBody.description role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource of a role under a pairing's scope effect: read questions: - Which resource is linked back from a role that sits under a pairing's scope resource? - Can I read the resource a scope-side role points to for one pairing? instructions: - text: Get the resource of role {role} under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show the role-linked resource for scope-side role {role}, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource of a role under a pairing's scope effect: destructive questions: - Can I delete the resource link from a role under a pairing's scope resource? - What removes the resource navigation of a scope-side role? instructions: - text: Delete the resource of role {role} under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Unlink the role-linked resource from scope-side role {role}, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource of a role under a pairing's scope effect: write questions: - How do I edit the resource that a scope-side role of a pairing points back to? - Can I rename the role-linked resource reached via a pairing's scope? instructions: - text: Rename the resource of role {role} under pairing {rrs}'s scope to {displayName}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id displayName: requestBody.displayName - text: Set origin system {originSystem} on the role-linked resource of {role}, pairing {rrs}. slots: originSystem: requestBody.originSystem role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get the environment via a scope-side role's resource effect: read questions: - Which hosting environment applies to the role-linked resource under a pairing's scope? - Is environment info available for a resource reached through a pairing's scope and then a role? instructions: - text: Look up the environment for scope-side role {role}'s linked resource, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show environment info for scope-side role {role}'s resource, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource of a role under a pairing's scope effect: write questions: - How do I refresh the resource a scope-side role of a pairing points to? - Can the role-linked resource under a pairing's scope be re-synced? instructions: - text: Refresh the resource of role {role} under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Trigger a refresh on scope-side role {role}'s linked resource, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes via a scope-side role's resource effect: read questions: - Which scopes exist on the resource of a role that sits under a pairing's scope? - Can I list root scopes on the role-linked resource reached through a pairing's scope? instructions: - text: List scopes on the resource of role {role} under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show scopes of scope-side role {role}'s linked resource for pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope via a scope-side role's resource effect: write questions: - How do I create a scope on the resource of a role under a pairing's scope? - Can a new scope on a scope-side role's linked resource be marked as root? instructions: - text: Create scope {displayName} on the resource of role {role} under pairing {rrs}'s scope. slots: displayName: requestBody.displayName role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Add a root scope ({isRootScope}) to scope-side role {role}'s linked resource, pairing {rrs}. slots: isRootScope: requestBody.isRootScope role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope via a scope-side role's resource effect: read questions: - What does a single scope on a scope-side role's linked resource contain? - Can I read one scope defined on the resource of a role under a pairing's scope? instructions: - text: Fetch scope {scope} defined on role {role}'s linked resource, pairing {rrs}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show scope {scope} of scope-side role {role}'s linked resource, pairing {rrs}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope via a scope-side role's resource effect: destructive questions: - Can I delete one scope from the resource of a role under a pairing's scope? - What removes a scope on a scope-side role's linked resource? instructions: - text: Remove scope {scope} defined on role {role}'s linked resource, pairing {rrs}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Drop scope {scope} from scope-side role {role}'s resource for pairing {rrs}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope via a scope-side role's resource effect: write questions: - Can I rename an existing scope on a scope-side role's linked resource? - How is the origin ID of a scope changed on the resource of a role under a pairing's scope? instructions: - text: Rename scope {scope} on role {role}'s linked resource under pairing {rrs}'s scope to {displayName}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id displayName: requestBody.displayName - text: Set origin ID {originId} on scope {scope} of scope-side role {role}'s resource, pairing {rrs}. slots: originId: requestBody.originId scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes via a scope-side role's resource effect: read questions: - How many scopes does the resource of a role under a pairing's scope have? - Can I get a scope total for a scope-side role's linked resource? instructions: - text: Count scopes on the resource of role {role} under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Tally scopes of scope-side role {role}'s linked resource, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions via a scope-side role's resource effect: read questions: - Which upload sessions exist on the resource of a role nested under a pairing's scope? - Can I list custom data sessions on a scope-then-role linked resource? instructions: - text: List upload sessions on the resource of role {role} under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show scope-then-role sessions for role {role}, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session via a scope-side role's resource effect: write questions: - How do I open an upload session on the resource of a role under a pairing's scope? - Can a scope-then-role linked resource get a new session tied to a review instance? instructions: - text: Create an upload session on role {role}'s linked resource under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Open a scope-then-role session for role {role}, pairing {rrs}, reference {referenceId}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id referenceId: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session via a scope-side role's resource effect: read questions: - What is the status of one session on a scope-then-role linked resource? - Can I check upload stats of a session on the resource of a role under a pairing's scope? instructions: - text: Get upload session {session} on role {role}'s linked resource under pairing {rrs}'s scope. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show scope-then-role session {session} for role {role}, pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session via a scope-side role's resource effect: destructive questions: - Can I delete a session on the resource of a role nested under a pairing's scope? - What removes one scope-then-role custom data upload session? instructions: - text: Delete upload session {session} on role {role}'s linked resource under pairing {rrs}'s scope. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Remove scope-then-role session {session}, role {role}, pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session via a scope-side role's resource effect: write questions: - How do I flag a scope-then-role upload session as finished? - Can I change a session's reference ID on the resource of a role under a pairing's scope? instructions: - text: 'Mark session {session} on role {role}''s linked resource under pairing {rrs}''s scope done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on scope-then-role session {session}, role {role}, pairing {rrs}. slots: referenceId: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a scope-then-role upload session effect: read questions: - Which files are in a session on the resource of a role under a pairing's scope? - Can I list uploaded files for a scope-then-role custom data session? instructions: - text: List files in session {session} on role {role}'s linked resource, pairing {rrs} scope. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Show scope-then-role files in session {session}, role {role}, pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a scope-then-role upload session effect: read questions: - How do I read the record for one file in a scope-then-role session? - What is stored about a single uploaded file on a scope-side role's linked resource? instructions: - text: Get file {file} in session {session} on role {role}'s linked resource, pairing {rrs} scope. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Fetch scope-then-role file {file}, session {session}, role {role}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content in a scope-then-role session effect: read questions: - Can I download the uploaded bytes of a file in a scope-then-role session? - Where do I get the media content of a file on a scope-side role's linked resource? instructions: - text: Download content of file {file}, session {session}, role {role}, under pairing {rrs}'s scope. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Pull scope-then-role file bytes for {file} in session {session}, role {role}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a scope-then-role session effect: write questions: - How do I overwrite a file's content in a scope-then-role upload session? - Can I replace uploaded bytes for a file on a scope-side role's linked resource? instructions: - text: Replace content of file {file}, session {session}, role {role}, under pairing {rrs}'s scope. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Overwrite scope-then-role file {file} bytes, session {session}, role {role}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a scope-then-role session effect: destructive questions: - Can I erase a file's stored content in a scope-then-role upload session? - What deletes uploaded bytes on a scope-side role's linked resource session file? instructions: - text: Delete content of file {file}, session {session}, role {role}, under pairing {rrs}'s scope. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Erase scope-then-role file {file} bytes, session {session}, role {role}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a scope-then-role upload session effect: read questions: - How many files were uploaded to a scope-then-role session? - Is there a file count for a session on a scope-side role's linked resource? instructions: - text: Count files in session {session} on role {role}'s linked resource, pairing {rrs} scope. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Tally scope-then-role files in session {session}, role {role}, pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a scope-then-role upload session effect: write questions: - How do I upload a file into a session on a scope-side role's linked resource? - Can I send custom data files to a scope-then-role session? instructions: - text: Upload a file to session {session} on role {role}'s linked resource, pairing {rrs} scope. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Send a file into scope-then-role session {session}, role {role}, pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions via a scope-side role's resource effect: read questions: - How many sessions exist on the resource of a role under a pairing's scope? - Can I count scope-then-role custom data sessions? instructions: - text: Count upload sessions on role {role}'s linked resource under pairing {rrs}'s scope. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id - text: Tally scope-then-role sessions for role {role}, pairing {rrs}. slots: role: path.accessPackageResourceRole-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles on a pairing's scope resource effect: read questions: - How many roles does the resource attached to a pairing's scope define? - Can I get a role total for one pairing's scope-side resource? instructions: - text: Count roles on the scope-side resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Tell me how many roles pairing {rrs}'s scope-side resource has. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes on a pairing's scope resource effect: read questions: - Which sibling scopes live on the resource attached to a pairing's scope? - Can I filter scopes on a pairing's scope-side resource to root scopes only? instructions: - text: List scopes on the scope-side resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Show all sibling scopes on pairing {rrs}'s scope-side resource. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a pairing's scope resource effect: write questions: - How do I add another scope to the resource attached to a pairing's scope? - Can a new sibling scope carry an origin ID from the resource's source system? instructions: - text: Create sibling scope {displayName} on pairing {rrs}'s scope-side resource. slots: displayName: requestBody.displayName rrs: path.accessPackageResourceRoleScope-id - text: Add a sibling scope with origin ID {originId} for pairing {rrs}. slots: originId: requestBody.originId rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope on a pairing's scope resource effect: read questions: - What does one sibling scope on a pairing's scope-side resource look like? - Can I read a single scope defined on the resource attached to a pairing's scope? instructions: - text: Get sibling scope {scope} on pairing {rrs}'s scope-side resource. slots: scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Show details of sibling scope {scope}, pairing {rrs}. slots: scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope on a pairing's scope resource effect: destructive questions: - Can I drop a sibling scope that lives next to a pairing's own scope? - What deletes one sibling scope on a pairing's scope-side resource? instructions: - text: Delete sibling scope {scope} from pairing {rrs}'s scope-side resource. slots: scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id - text: Remove scope {scope} on the scope-side resource of pairing {rrs}. slots: scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope on a pairing's scope resource effect: write questions: - How do I rename a sibling scope on a pairing's scope-side resource? - Can I change whether a sibling scope is the root scope? instructions: - text: Rename sibling scope {scope} of pairing {rrs} to {displayName}. slots: scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id displayName: requestBody.displayName - text: Set isRootScope {isRootScope} on sibling scope {scope}, pairing {rrs}. slots: isRootScope: requestBody.isRootScope scope: path.accessPackageResourceScope-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes on a pairing's scope resource effect: read questions: - How many sibling scopes does a pairing's scope-side resource have? - Can I count every scope on the resource attached to a pairing's scope? instructions: - text: Count sibling scopes on pairing {rrs}'s scope-side resource. slots: rrs: path.accessPackageResourceRoleScope-id - text: Tell me the scope total on the scope-side resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions on a pairing's scope resource effect: read questions: - Which custom data upload sessions exist on the resource attached to a pairing's scope? - Can I filter scope-side upload sessions by the access review they belong to? instructions: - text: List upload sessions on the scope-side resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Show scope-side sessions for pairing {rrs}, oldest first. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a pairing's scope resource effect: write questions: - How do I open an upload session on a pairing's scope-side resource? - Can a scope-side session be tied to a specific access review instance? instructions: - text: Create an upload session on the scope-side resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Open a scope-side session for pairing {rrs} with reference {referenceId}. slots: rrs: path.accessPackageResourceRoleScope-id referenceId: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session on a pairing's scope resource effect: read questions: - What status does one scope-side upload session report? - Can I check if a session on a pairing's scope-side resource is done? instructions: - text: Get scope-side upload session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Show status and stats of session {session} on pairing {rrs}'s scope-side resource. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session on a pairing's scope resource effect: destructive questions: - Can I delete a custom data session from a pairing's scope-side resource? - What removes one scope-side upload session? instructions: - text: Delete scope-side upload session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Remove session {session} from the scope-side resource of pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session on a pairing's scope resource effect: write questions: - How do I close out a scope-side upload session once files are in? - Can I edit the reference ID on a session attached to a pairing's scope resource? instructions: - text: 'Mark scope-side session {session} for pairing {rrs} as done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on scope-side session {session}, pairing {rrs}. slots: referenceId: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a pairing's scope-side session effect: read questions: - Which files have been uploaded in a scope-side session for a pairing? - Can I page through files in a session on a pairing's scope-side resource? instructions: - text: List files in scope-side session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Show uploaded files in session {session} on pairing {rrs}'s scope-side resource. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a pairing's scope-side session effect: read questions: - How do I look up a single uploaded file in a scope-side session? - What record is kept for one file on a pairing's scope-side resource session? instructions: - text: Get file {file} in scope-side session {session} for pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Fetch file record {file}, session {session}, pairing {rrs} scope-side resource. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content in a scope-side session effect: read questions: - Can I download the uploaded content of a file in a scope-side session? - Where are the raw bytes of a file on a pairing's scope-side resource session? instructions: - text: Download content of file {file} in scope-side session {session}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Pull raw scope-side file bytes for {file}, session {session}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a scope-side session effect: write questions: - How do I overwrite a file's content in a scope-side upload session? - Can I re-send the bytes of a file on a pairing's scope-side resource session? instructions: - text: Replace content of file {file} in scope-side session {session}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Overwrite scope-side file {file} bytes in session {session} for pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a scope-side session effect: destructive questions: - Can I wipe a file's stored content in a scope-side upload session? - What clears uploaded bytes from a file on a pairing's scope-side resource? instructions: - text: Delete content of file {file} in scope-side session {session}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Wipe scope-side file {file} bytes from session {session}, pairing {rrs}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a pairing's scope-side session effect: read questions: - How many files are in a scope-side upload session? - Is there a file tally for a session on a pairing's scope-side resource? instructions: - text: Count files in scope-side session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Tally uploaded files, session {session}, pairing {rrs} scope-side resource. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a pairing's scope-side session effect: write questions: - How do I upload a file into a session on a pairing's scope-side resource? - Can I add a custom data file to an open scope-side session? instructions: - text: Upload a file to scope-side session {session} for pairing {rrs}. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id - text: Send a custom data file into session {session}, pairing {rrs} scope-side resource. slots: session: path.customDataProvidedResourceUploadSession-id rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/{accessPackageResourceRoleScope-id}/scope/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a pairing's scope resource effect: read questions: - How many upload sessions does a pairing's scope-side resource have? - Can I count custom data sessions on the resource attached to a pairing's scope? instructions: - text: Count upload sessions on the scope-side resource of pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id - text: Tell me the scope-side session total for pairing {rrs}. slots: rrs: path.accessPackageResourceRoleScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resourceRoleScopes/$count'].get update: x-apievangelist-phrasing: intent: Count resource role scopes effect: read questions: - How many role-scope pairings exist in entitlement management? - Can I get the total number of resource role scopes across access packages? instructions: - text: Count all resource role scopes. - text: Tell me how many role-scope pairings entitlement management holds. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources'].get update: x-apievangelist-phrasing: intent: List resources in access package catalogs effect: read questions: - Which resources have been added to my access package catalogs? - Can I search catalog resources by display name or origin system? instructions: - text: List all catalog resources. - text: Show catalog resources sorted by display name. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources'].post update: x-apievangelist-phrasing: intent: Add a resource to entitlement management effect: write questions: - How do I register a new resource such as a group or app for access packages? - Can I set a resource's origin ID and origin system when I create it? instructions: - text: Create a catalog resource named {displayName} with origin ID {originId}. slots: displayName: requestBody.displayName originId: requestBody.originId - text: Add resource {displayName} from origin system {originSystem}. slots: displayName: requestBody.displayName originSystem: requestBody.originSystem method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}'].get update: x-apievangelist-phrasing: intent: Get a catalog resource effect: read questions: - What details does entitlement management hold for one catalog resource? - Can I expand a single catalog resource's roles and scopes in one call? instructions: - text: Get catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Show catalog resource {resource} with its roles expanded. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}'].delete update: x-apievangelist-phrasing: intent: Delete a catalog resource effect: destructive questions: - Can I remove a resource from entitlement management entirely? - What happens to a catalog resource when I delete it? instructions: - text: Delete catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Remove resource {resource} from the access package catalogs. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}'].patch update: x-apievangelist-phrasing: intent: Update a catalog resource effect: write questions: - How do I rename a resource already registered in a catalog? - Can I change the description or attributes of an existing catalog resource? instructions: - text: Rename catalog resource {resource} to {displayName}. slots: resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set description {description} on catalog resource {resource}. slots: description: requestBody.description resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/environment'].get update: x-apievangelist-phrasing: intent: Get the environment of a catalog resource effect: read questions: - Which environment does a catalog resource live in? - Can I see environment information for one resource in my catalogs? instructions: - text: Get the environment of catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Show which environment catalog resource {resource} belongs to. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a catalog resource effect: write questions: - How do I refresh a catalog resource so its details are current? - Can I trigger a refresh on one resource in entitlement management? instructions: - text: Refresh catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Trigger a refresh of resource {resource} in the catalog. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles'].get update: x-apievangelist-phrasing: intent: List roles of a catalog resource effect: read questions: - Which roles can be granted on a catalog resource, like group member or owner? - Can I filter a catalog resource's roles by origin ID? instructions: - text: List roles of catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Show assignable roles on resource {resource}. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles'].post update: x-apievangelist-phrasing: intent: Add a role to a catalog resource effect: write questions: - How do I define a new role on a resource in my catalog? - Can a new catalog resource role carry a description and origin system? instructions: - text: Create role {displayName} on catalog resource {resource}. slots: displayName: requestBody.displayName resource: path.accessPackageResource-id - text: Add a role with origin ID {originId} to resource {resource}. slots: originId: requestBody.originId resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role of a catalog resource effect: read questions: - What does one role on a catalog resource contain? - Can I read the origin ID of a single catalog resource role? instructions: - text: Get role {role} of catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show details of resource {resource} role {role}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role of a catalog resource effect: destructive questions: - Can I remove a role from a resource in my catalog? - What deletes one role defined on a catalog resource? instructions: - text: Delete role {role} from top-level entitlement resource {resource}, outside any catalog path. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Remove resource {resource}'s role {role}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role of a catalog resource effect: write questions: - How do I rename a role on a resource from the top-level resources list? - Can I change a catalog resource role's description? instructions: - text: Rename role {role} on catalog resource {resource} to {displayName}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set description {description} on resource {resource} role {role}. slots: description: requestBody.description resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource a catalog role belongs to effect: read questions: - Which resource does a given role of a catalog resource point back to? - Can I read the role's own resource record from the role side? instructions: - text: Get the own resource of role {role} on catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show what resource role {role} of {resource} points back to. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink a catalog role's own resource effect: destructive questions: - Can I delete the resource navigation on a catalog resource's role? - What removes a role's back-link to its own resource? instructions: - text: Delete the own resource link of role {role} on catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Unlink role {role}'s back-pointed resource under {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update a catalog role's own resource effect: write questions: - How do I edit the resource record reached from a catalog role? - Can I rename a resource through its role's back-link? instructions: - text: Rename the own resource of role {role} on {resource} to {displayName}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set origin system {originSystem} on role {role}'s back-pointed resource, catalog resource {resource}. slots: originSystem: requestBody.originSystem role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment via a catalog role's resource effect: read questions: - Which environment is the resource of a catalog role in? - Can I look up environment details starting from a resource role? instructions: - text: Get the environment of role {role}'s own resource on catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show environment info via role {role} back-link, resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a catalog role's own resource effect: write questions: - How do I refresh the resource reached from one of its roles? - Can I trigger a refresh starting from a catalog resource role? instructions: - text: Refresh the own resource of role {role} on catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Run a refresh via role {role}'s back-link on resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].get update: x-apievangelist-phrasing: intent: List scopes via a catalog role's resource effect: read questions: - Which scopes are on the resource reached through a catalog role? - Can I list root scopes starting from a resource role's back-link? instructions: - text: List scopes on role {role}'s own resource, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show scopes via role {role} back-link on resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope via a catalog role's resource effect: write questions: - How do I create a scope on a resource reached through one of its roles? - Can a scope created from the role side be flagged as root scope? instructions: - text: Create scope {displayName} on role {role}'s own resource, catalog resource {resource}. slots: displayName: requestBody.displayName role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Add a scope with origin ID {originId} via role {role} back-link on {resource}. slots: originId: requestBody.originId role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope in a catalog role-scope drilldown effect: read questions: - What does one scope look like when I drill down from a catalog resource into a role? - Can I read a single scope via a resource's role drilldown? instructions: - text: From top-level resource {resource}, drill into role {role} and get scope {scope}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show drilldown scope {scope}, role {role}, resource {resource}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope in a catalog role-scope drilldown effect: destructive questions: - Can I delete a scope reached by drilling down through a catalog role? - What removes one scope on the resource behind a catalog resource's role? instructions: - text: From top-level resource {resource}, drill into role {role} and delete scope {scope}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Remove drilldown scope {scope}, role {role}, resource {resource}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope in a catalog role-scope drilldown effect: write questions: - How do I rename a scope reached through a catalog resource's role? - Can I toggle the root flag on a scope from the role drilldown? instructions: - text: Rename drilldown scope {scope} via role {role} of {resource} to {displayName}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set isRootScope {isRootScope} on scope {scope}, role {role}, catalog resource {resource}. slots: isRootScope: requestBody.isRootScope scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource at the end of a role-scope drilldown effect: read questions: - Which resource sits at the bottom of a catalog resource, role, then scope drilldown? - Can I read the scope's resource after drilling from a resource into a role? instructions: - text: Get the resource of drilldown scope {scope}, role {role}, catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show the bottom resource for resource {resource} role {role} scope {scope} drilldown. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource at the end of a role-scope drilldown effect: destructive questions: - Can I delete the resource link of a scope reached via a catalog role drilldown? - What removes the bottom resource navigation in a drilldown path? instructions: - text: Delete the resource link of drilldown scope {scope}, role {role}, catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Unlink the bottom resource of resource {resource} role {role} scope {scope} drilldown. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource at the end of a role-scope drilldown effect: write questions: - How do I edit the scope's resource at the bottom of a catalog role drilldown? - Can I rename the bottom resource in a drilldown path? instructions: - text: Rename the bottom resource of drilldown scope {scope}, role {role}, {resource} to {displayName}. slots: scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set description {description} on the drilldown resource, resource {resource}, role {role}, scope {scope}. slots: description: requestBody.description resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment at the end of a role-scope drilldown effect: read questions: - Which environment is the bottom resource of a drilldown path in? - Can I check environment details from a drilldown through a role and a scope? instructions: - text: Get the environment of the drilldown resource, resource {resource}, role {role}, scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Show bottom-resource environment for {resource} role {role} scope {scope} drilldown. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource at the end of a role-scope drilldown effect: write questions: - How do I refresh the bottom resource of a drilldown path? - Can I trigger a refresh after drilling through a catalog role and scope? instructions: - text: Refresh the drilldown resource, resource {resource}, role {role}, scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Run a refresh on the bottom resource of {resource} role {role} scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions at a role-scope drilldown resource effect: read questions: - Which upload sessions exist at the bottom of a catalog drilldown path? - Can I filter drilldown upload sessions by review reference ID? instructions: - text: List upload sessions at drilldown resource {resource}, role {role}, scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Show drilldown path sessions for {resource}, role {role}, scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session at a role-scope drilldown resource effect: write questions: - How do I open a custom data session at the bottom of a drilldown path? - Can a drilldown session reference an access review instance? instructions: - text: Create an upload session at drilldown resource {resource}, role {role}, scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Open a drilldown path session for {resource} role {role} scope {scope} with reference {referenceId}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id referenceId: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session at a role-scope drilldown resource effect: read questions: - What status does one drilldown path upload session show? - Can I check the stats of a session at the bottom of a catalog role drilldown? instructions: - text: Get drilldown session {session}, resource {resource}, role {role}, scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Show drilldown path session {session} status for {resource} role {role} scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session at a role-scope drilldown resource effect: destructive questions: - Can I remove a custom data session at the bottom of a drilldown path? - What deletes a drilldown upload session reached through a catalog role? instructions: - text: Delete drilldown session {session}, resource {resource}, role {role}, scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Remove drilldown path session {session} for {resource} role {role} scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session at a role-scope drilldown resource effect: write questions: - How do I mark a drilldown path session as upload complete? - Can I change the reference ID on a drilldown session? instructions: - text: 'Mark drilldown session {session}, resource {resource}, role {role}, scope {scope} done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on drilldown path session {session}, {resource} role {role} scope {scope}. slots: referenceId: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a role-scope drilldown session effect: read questions: - Which files are in a session at the bottom of a drilldown path? - Can I list uploaded files for a catalog role drilldown session? instructions: - text: List files in drilldown session {session}, resource {resource}, role {role}, scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Show drilldown path files, session {session}, {resource} role {role} scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a role-scope drilldown session effect: read questions: - How do I read one uploaded file record in a drilldown path session? - What is stored for a single file at the bottom of a catalog role drilldown? instructions: - text: Get file {file} in drilldown session {session}, resource {resource}, role {role}, scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Fetch drilldown path file {file}, session {session}, {resource} role {role} scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content in a role-scope drilldown session effect: read questions: - Can I download a file's bytes from a drilldown path session? - Where is the raw content of a file at the bottom of a catalog role drilldown? instructions: - text: Download content of file {file}, drilldown session {session}, {resource} role {role} scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Pull drilldown path bytes of file {file}, session {session}, resource {resource}, role {role}, scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a role-scope drilldown session effect: write questions: - How do I overwrite a file's content in a drilldown path session? - Can I re-upload file bytes at the bottom of a catalog role drilldown? instructions: - text: Replace content of file {file}, drilldown session {session}, {resource} role {role} scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Overwrite drilldown path file {file} bytes, session {session}, resource {resource}, role {role}, scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a role-scope drilldown session effect: destructive questions: - Can I erase a file's content from a drilldown path session? - What clears stored bytes of a file at the bottom of a catalog role drilldown? instructions: - text: Delete content of file {file}, drilldown session {session}, {resource} role {role} scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Erase drilldown path file {file} bytes, session {session}, resource {resource}, role {role}, scope {scope}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a role-scope drilldown session effect: read questions: - How many files are in a drilldown path session? - Is there a file count for a session at the bottom of a catalog role drilldown? instructions: - text: Count files in drilldown session {session}, resource {resource}, role {role}, scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Tally drilldown path files, session {session}, {resource} role {role} scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a role-scope drilldown session effect: write questions: - How do I upload a file to a session at the bottom of a drilldown path? - Can I push custom data into a catalog role drilldown session? instructions: - text: Upload a file to drilldown session {session}, resource {resource}, role {role}, scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Send a file into drilldown path session {session}, {resource} role {role} scope {scope}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions at a role-scope drilldown resource effect: read questions: - How many sessions exist at the bottom of a drilldown path? - Can I count drilldown custom data sessions under a catalog role and scope? instructions: - text: Count upload sessions at drilldown resource {resource}, role {role}, scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id - text: Tally drilldown path sessions for {resource} role {role} scope {scope}. slots: resource: path.accessPackageResource-id role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes via a catalog role's resource effect: read questions: - How many scopes are on the resource reached through a catalog role? - Can I get a scope total from the role side of a catalog resource? instructions: - text: Count scopes on role {role}'s own resource, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Tally scopes via role {role} back-link on {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions via a catalog role's resource effect: read questions: - Which upload sessions exist on the resource behind a catalog resource's role? - Can I list role back-link sessions filtered by review reference? instructions: - text: List upload sessions on role {role}'s own resource, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show back-link sessions via role {role} of {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session via a catalog role's resource effect: write questions: - How do I open an upload session from a catalog resource's role back-link? - Can a role back-link session be tied to an access review instance? instructions: - text: Create an upload session on role {role}'s own resource, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Open a back-link session via role {role} of {resource} with reference {referenceId}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id referenceId: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session via a catalog role's resource effect: read questions: - What status does a session reached through a catalog role back-link report? - Can I check if a role back-link upload session finished? instructions: - text: Get back-link session {session} via role {role} of catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show status of session {session} on role {role}'s own resource, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session via a catalog role's resource effect: destructive questions: - Can I delete a session reached through a catalog role back-link? - What removes one upload session on a role's own resource? instructions: - text: Delete back-link session {session} via role {role} of catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Remove session {session} on role {role}'s own resource, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session via a catalog role's resource effect: write questions: - How do I close a session reached through a catalog role back-link? - Can I edit the reference ID of a role back-link session? instructions: - text: 'Mark back-link session {session} via role {role} of {resource} done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on session {session}, role {role}'s own resource, {resource}. slots: referenceId: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalog role back-link session effect: read questions: - Which files are in a session reached through a catalog role back-link? - Can I page through files on a role's own resource session? instructions: - text: List files in back-link session {session}, role {role}, catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Show files for session {session} on role {role}'s own resource, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a catalog role back-link session effect: read questions: - How do I read one file record from a role back-link session? - What is kept about a single file on a catalog role's own resource session? instructions: - text: Get file {file} in back-link session {session}, role {role}, catalog resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Fetch file {file}, session {session}, role {role}'s own resource, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content in a catalog role back-link session effect: read questions: - Can I download a file's bytes from a role back-link upload session? - Where is the raw content of a file on a catalog role's own resource session? instructions: - text: Download content of file {file}, back-link session {session}, role {role}, resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Pull bytes of file {file}, session {session}, role {role}'s own resource, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a catalog role back-link session effect: write questions: - How do I overwrite a file's bytes in a role back-link session? - Can I replace content of a file on a catalog role's own resource session? instructions: - text: Replace content of file {file}, back-link session {session}, role {role}, resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Overwrite bytes of file {file}, session {session}, role {role}'s own resource, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a catalog role back-link session effect: destructive questions: - Can I wipe a file's content in a role back-link session? - What erases bytes of a file on a catalog role's own resource session? instructions: - text: Delete content of file {file}, back-link session {session}, role {role}, resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Wipe bytes of file {file}, session {session}, role {role}'s own resource, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a catalog role back-link session effect: read questions: - How many files are in a role back-link upload session? - Is there a file tally for a session on a catalog role's own resource? instructions: - text: Count files in back-link session {session}, role {role}, catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Tally files for session {session}, role {role}'s own resource, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a catalog role back-link session effect: write questions: - How do I upload a file into a role back-link session? - Can I send a custom data file to a session on a catalog role's own resource? instructions: - text: Upload a file to back-link session {session}, role {role}, catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Send a file into session {session} on role {role}'s own resource, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions via a catalog role's resource effect: read questions: - How many sessions exist on the resource behind a catalog role back-link? - Can I count upload sessions from the role side of a catalog resource? instructions: - text: Count upload sessions on role {role}'s own resource, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id - text: Tally back-link sessions via role {role} of {resource}. slots: role: path.accessPackageResourceRole-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles of a catalog resource effect: read questions: - How many roles does a catalog resource define? - Can I get a quick role total for one resource in my catalogs? instructions: - text: Count roles of catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Tell me how many assignable roles resource {resource} has. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes'].get update: x-apievangelist-phrasing: intent: List scopes of a catalog resource effect: read questions: - Which scopes does a catalog resource expose, such as an app or site scope? - Can I filter a catalog resource's scopes to the root scope? instructions: - text: List scopes of catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Show every scope defined directly on resource {resource}. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes'].post update: x-apievangelist-phrasing: intent: Add a scope to a catalog resource effect: write questions: - How do I add a scope directly to a resource in my catalog? - Can a new catalog resource scope be the root scope? instructions: - text: Create scope {displayName} directly on catalog resource {resource}. slots: displayName: requestBody.displayName resource: path.accessPackageResource-id - text: Add a root scope ({isRootScope}) to resource {resource}. slots: isRootScope: requestBody.isRootScope resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].get update: x-apievangelist-phrasing: intent: Get a scope of a catalog resource effect: read questions: - What does one scope defined directly on a catalog resource contain? - Can I read the origin system of a single catalog resource scope? instructions: - text: Get scope {scope} of catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show details of resource {resource} scope {scope}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].delete update: x-apievangelist-phrasing: intent: Delete a scope of a catalog resource effect: destructive questions: - Can I remove a scope defined directly on a catalog resource? - What deletes one scope from a resource in my catalog? instructions: - text: Delete scope {scope} directly from top-level entitlement resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Remove resource {resource}'s scope {scope}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}'].patch update: x-apievangelist-phrasing: intent: Update a scope of a catalog resource effect: write questions: - How do I rename a scope defined directly on a catalog resource? - Can I change the description of an existing catalog resource scope? instructions: - text: Give scope {scope} on top-level entitlement resource {resource} the new name {displayName}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set description {description} on resource {resource} scope {scope}. slots: description: requestBody.description resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the parent resource of a catalog scope effect: read questions: - Which parent resource does a catalog scope hang from? - Can I read the parent resource record starting from one of its scopes? instructions: - text: Get the parent resource of scope {scope} on catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show which parent resource scope {scope} of {resource} hangs from. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink a catalog scope's parent resource effect: destructive questions: - Can I delete the parent resource navigation on a catalog scope? - What cuts a scope's link up to its parent resource? instructions: - text: Delete the parent resource link of scope {scope} on catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Cut scope {scope}'s link up to its parent under {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update a catalog scope's parent resource effect: write questions: - How do I edit a parent resource by navigating from one of its scopes? - Can I rename the parent resource that a scope hangs from? instructions: - text: Rename the parent resource of scope {scope} on {resource} to {displayName}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set origin system {originSystem} on the parent of scope {scope}, catalog resource {resource}. slots: originSystem: requestBody.originSystem scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment via a catalog scope's parent effect: read questions: - Which environment is the parent resource of a catalog scope in? - Can I look up environment details starting from a scope and going up to its parent? instructions: - text: Get the environment of scope {scope}'s parent resource on catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show environment info for the parent of scope {scope}, resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh a catalog scope's parent resource effect: write questions: - How do I refresh a parent resource starting from one of its scopes? - Can a refresh be triggered on the resource a catalog scope hangs from? instructions: - text: Refresh the parent resource of scope {scope} on catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Run a refresh on the parent of scope {scope}, resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].get update: x-apievangelist-phrasing: intent: List roles on a catalog scope's parent resource effect: read questions: - Which roles exist on the parent resource that a catalog scope hangs from? - Can I list roles by going up from a scope to its parent resource? instructions: - text: List roles on the parent resource of scope {scope}, catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show roles on the parent of scope {scope} under {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles'].post update: x-apievangelist-phrasing: intent: Add a role on a catalog scope's parent resource effect: write questions: - Starting from the top-level resources list, how do I add a new role to the resource behind one of its scopes? - Can a role added from a scope's parent resource carry an origin ID? instructions: - text: Create role {displayName} on the parent resource of scope {scope}, catalog resource {resource}. slots: displayName: requestBody.displayName scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Add a role with origin ID {originId} on the parent of scope {scope} under {resource}. slots: originId: requestBody.originId scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].get update: x-apievangelist-phrasing: intent: Get a role on a catalog scope's parent resource effect: read questions: - What does one role look like on the parent resource that a scope hangs from? - Can I read a single role by going up from a catalog scope to its parent? instructions: - text: Read role {role} defined on scope {scope}'s parent, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show parent-level role {role} for scope {scope} under {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].delete update: x-apievangelist-phrasing: intent: Delete a role on a catalog scope's parent resource effect: destructive questions: - Can I delete a role on the parent resource that a catalog scope hangs from? - What drops one role reached by going up from a scope to its parent? instructions: - text: Delete role {role} on the parent of scope {scope}, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Drop parent-level role {role} for scope {scope} under {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}'].patch update: x-apievangelist-phrasing: intent: Update a role on a catalog scope's parent resource effect: write questions: - Can I rename a role on the parent resource of a catalog scope? - How is a parent-level role's description changed when navigating from a scope? instructions: - text: Rename parent-level role {role} of scope {scope} under {resource} to {displayName}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set description {description} on role {role}, parent of scope {scope}, catalog resource {resource}. slots: description: requestBody.description role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].get update: x-apievangelist-phrasing: intent: Get the resource at the end of a scope-role descent effect: read questions: - Which resource is reached last in a descent chain from a catalog scope down through a role? - Can I fetch the final resource record after descending from a scope's parent into one of its roles? instructions: - text: Get the resource of descent role {role}, scope {scope}, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show the final descent chain resource for {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].delete update: x-apievangelist-phrasing: intent: Unlink the resource at the end of a scope-role descent effect: destructive questions: - Can I cut the final resource link in a descent chain that starts at a catalog scope? - What unlinks the last resource of a scope-first descent chain? instructions: - text: Delete the resource link of descent role {role}, scope {scope}, catalog resource {resource}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Unlink the final descent chain resource for {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource'].patch update: x-apievangelist-phrasing: intent: Update the resource at the end of a scope-role descent effect: write questions: - How do I edit the final resource reached through a scope-first descent chain? - Can I rename the last resource in a descent chain from a catalog scope? instructions: - text: Rename the final resource of descent role {role}, scope {scope}, {resource} to {displayName}. slots: role: path.accessPackageResourceRole-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id displayName: requestBody.displayName - text: Set description {description} on the descent chain resource, resource {resource}, scope {scope}, role {role}. slots: description: requestBody.description resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/environment'].get update: x-apievangelist-phrasing: intent: Get environment at the end of a scope-role descent effect: read questions: - Which environment hosts the final resource of a scope-first descent chain? - Is environment info available at the end of a descent chain from a catalog scope? instructions: - text: Get the environment of the descent chain resource, resource {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Show final-resource environment for {resource} scope {scope} role {role} descent. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/microsoft.graph.refresh'].post update: x-apievangelist-phrasing: intent: Refresh the resource at the end of a scope-role descent effect: write questions: - How do I refresh the final resource of a scope-first descent chain? - Can a refresh be run at the end of a descent chain from a catalog scope? instructions: - text: Refresh the descent chain resource, resource {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Run a refresh on the final resource of descent {resource} scope {scope} role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions at a scope-role descent resource effect: read questions: - Which upload sessions exist at the bottom of a catalog descent chain? - Can I filter descent upload sessions by review reference ID? instructions: - text: List upload sessions at descent resource {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Show descent chain sessions for {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session at a scope-role descent resource effect: write questions: - How do I open a custom data session at the bottom of a descent chain? - Can a descent session reference an access review instance? instructions: - text: Create an upload session at descent resource {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Open a descent chain session for {resource} scope {scope} role {role} with reference {referenceId}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id referenceId: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session at a scope-role descent resource effect: read questions: - What status does one descent chain upload session show? - Can I check the stats of a session at the bottom of a catalog scope descent? instructions: - text: Get descent session {session}, resource {resource}, scope {scope}, role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Show descent chain session {session} status for {resource} scope {scope} role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session at a scope-role descent resource effect: destructive questions: - Can I remove a custom data session at the bottom of a descent chain? - What deletes a descent upload session reached through a catalog scope? instructions: - text: Delete descent session {session}, resource {resource}, scope {scope}, role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Remove descent chain session {session} for {resource} scope {scope} role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session at a scope-role descent resource effect: write questions: - How do I mark a descent chain session as upload complete? - Can I change the reference ID on a descent session? instructions: - text: 'Mark descent session {session}, resource {resource}, scope {scope}, role {role} done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on descent chain session {session}, {resource} scope {scope} role {role}. slots: referenceId: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a scope-role descent session effect: read questions: - Which files are in a session at the bottom of a descent chain? - Can I list uploaded files for a catalog scope descent session? instructions: - text: List files in descent session {session}, resource {resource}, scope {scope}, role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Show descent chain files, session {session}, {resource} scope {scope} role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a scope-role descent session effect: read questions: - How do I read one uploaded file record in a descent chain session? - What is stored for a single file at the bottom of a catalog scope descent? instructions: - text: Get file {file} in descent session {session}, resource {resource}, scope {scope}, role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Fetch descent chain file {file}, session {session}, {resource} scope {scope} role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content in a scope-role descent session effect: read questions: - Can I download a file's bytes from a descent chain session? - Where is the raw content of a file at the bottom of a catalog scope descent? instructions: - text: Download content of file {file}, descent session {session}, {resource} scope {scope} role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Pull descent chain bytes of file {file}, session {session}, resource {resource}, scope {scope}, role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a scope-role descent session effect: write questions: - How do I overwrite a file's content in a descent chain session? - Can I re-upload file bytes at the bottom of a catalog scope descent? instructions: - text: Replace content of file {file}, descent session {session}, {resource} scope {scope} role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Overwrite descent chain file {file} bytes, session {session}, resource {resource}, scope {scope}, role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a scope-role descent session effect: destructive questions: - Can I erase a file's content from a descent chain session? - What clears stored bytes of a file at the bottom of a catalog scope descent? instructions: - text: Delete content of file {file}, descent session {session}, {resource} scope {scope} role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Erase descent chain file {file} bytes, session {session}, resource {resource}, scope {scope}, role {role}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a scope-role descent session effect: read questions: - How many files are in a descent chain session? - Is there a file count for a session at the bottom of a catalog scope descent? instructions: - text: Count files in descent session {session}, resource {resource}, scope {scope}, role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Tally descent chain files, session {session}, {resource} scope {scope} role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a scope-role descent session effect: write questions: - How do I upload a file to a session at the bottom of a descent chain? - Can I push custom data into a catalog scope descent session? instructions: - text: Upload a file to descent session {session}, resource {resource}, scope {scope}, role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Send a file into descent chain session {session}, {resource} scope {scope} role {role}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/{accessPackageResourceRole-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions at a scope-role descent resource effect: read questions: - How many sessions exist at the end of a scope-first descent chain? - Is there a session tally for the final resource of a catalog descent chain? instructions: - text: Count upload sessions at descent resource {resource}, scope {scope}, role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id - text: Tally descent chain sessions for {resource} scope {scope} role {role}. slots: resource: path.accessPackageResource-id scope: path.accessPackageResourceScope-id role: path.accessPackageResourceRole-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/roles/$count'].get update: x-apievangelist-phrasing: intent: Count roles on a catalog scope's parent resource effect: read questions: - How many roles are on the parent resource that a catalog scope hangs from? - Is there a role tally when going up from a scope to its parent resource? instructions: - text: Count roles on the parent resource of scope {scope}, catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Tally parent-level roles for scope {scope} under {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions on a catalog scope's parent effect: read questions: - Which upload sessions exist on the parent resource a catalog scope hangs from? - Can I filter a scope's parent-resource sessions by review reference? instructions: - text: List upload sessions on the parent resource of scope {scope}, catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show parent-level sessions for scope {scope} under {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a catalog scope's parent effect: write questions: - How do I open an upload session on the parent resource of a catalog scope? - Can a parent-level session opened from a scope reference an access review instance? instructions: - text: Create an upload session on the parent resource of scope {scope}, catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Open a parent-level session for scope {scope} under {resource} with reference {referenceId}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id referenceId: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session on a catalog scope's parent effect: read questions: - What status does a session on a scope's parent resource report? - Can I tell if a parent-level upload session, reached from a scope, is done? instructions: - text: Get parent-level session {session} for scope {scope} under catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show status of session {session} on the parent of scope {scope}, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session on a catalog scope's parent effect: destructive questions: - Can I delete a session on the parent resource that a scope hangs from? - What drops one parent-level upload session reached from a catalog scope? instructions: - text: Delete parent-level session {session} for scope {scope} under catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Drop session {session} on the parent of scope {scope}, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session on a catalog scope's parent effect: write questions: - How do I finish off a parent-level session reached from a catalog scope? - Can I edit the reference ID of a session on a scope's parent resource? instructions: - text: 'Mark parent-level session {session} for scope {scope} under {resource} done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on session {session}, parent of scope {scope}, {resource}. slots: referenceId: requestBody.referenceId session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalog scope's parent-level session effect: read questions: - Which files are in a session on the parent resource of a catalog scope? - Can I page through files of a parent-level session reached from a scope? instructions: - text: List files in parent-level session {session}, scope {scope}, catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Show files for session {session} on the parent of scope {scope}, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a catalog scope's parent-level session effect: read questions: - How do I read one file record from a session on a scope's parent resource? - What is kept about a single file in a parent-level session reached from a scope? instructions: - text: Get file {file} in parent-level session {session}, scope {scope}, catalog resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Fetch file {file}, session {session}, parent of scope {scope}, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content in a scope's parent-level session effect: read questions: - Can I download a file's bytes from a session on a catalog scope's parent resource? - Where is the raw content of a file in a parent-level session reached from a scope? instructions: - text: Download content of file {file}, parent-level session {session}, scope {scope}, resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Pull bytes of file {file}, session {session}, parent of scope {scope}, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a scope's parent-level session effect: write questions: - How do I overwrite a file's bytes in a session on a scope's parent resource? - Can I replace content of a file in a parent-level session reached from a catalog scope? instructions: - text: Replace content of file {file}, parent-level session {session}, scope {scope}, resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Overwrite bytes of file {file}, session {session}, parent of scope {scope}, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a scope's parent-level session effect: destructive questions: - Can I wipe a file's content in a session on a catalog scope's parent resource? - What erases file bytes in a parent-level session reached from a scope? instructions: - text: Delete content of file {file}, parent-level session {session}, scope {scope}, resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Wipe bytes of file {file}, session {session}, parent of scope {scope}, {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a scope's parent-level session effect: read questions: - How many files are in a session on a scope's parent resource? - Is there a file tally for a parent-level session reached from a catalog scope? instructions: - text: Count files in parent-level session {session}, scope {scope}, catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Tally files for session {session}, parent of scope {scope}, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a scope's parent-level session effect: write questions: - How do I upload a file into a session on a catalog scope's parent resource? - Can I push a custom data file into a parent-level session reached from a scope? instructions: - text: Upload a file to parent-level session {session}, scope {scope}, catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Send a file into session {session} on the parent of scope {scope}, {resource}. slots: session: path.customDataProvidedResourceUploadSession-id scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/{accessPackageResourceScope-id}/resource/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a catalog scope's parent effect: read questions: - How many sessions exist on the parent resource a catalog scope hangs from? - Is there a session tally for a scope's parent resource? instructions: - text: Count upload sessions on the parent resource of scope {scope}, catalog resource {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id - text: Tally parent-level sessions for scope {scope} under {resource}. slots: scope: path.accessPackageResourceScope-id resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/scopes/$count'].get update: x-apievangelist-phrasing: intent: Count scopes of a catalog resource effect: read questions: - How many scopes are defined directly on a catalog resource? - Is there a quick scope tally I can pull for a single catalog resource? instructions: - text: Count scopes of catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Tell me how many scopes resource {resource} defines directly. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions'].get update: x-apievangelist-phrasing: intent: List upload sessions on a catalog resource effect: read questions: - Which custom data upload sessions have been opened directly on a catalog resource? - Can I filter a catalog resource's upload sessions by access review reference? instructions: - text: List upload sessions directly on catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Show resource {resource}'s own custom data sessions, newest first. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions'].post update: x-apievangelist-phrasing: intent: Start an upload session on a catalog resource effect: write questions: - How do I start uploading custom data for a resource in my catalog? - Can a direct catalog resource session reference an access review instance? instructions: - text: Create an upload session directly on catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Open a custom data session for resource {resource} with reference {referenceId}. slots: resource: path.accessPackageResource-id referenceId: requestBody.referenceId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].get update: x-apievangelist-phrasing: intent: Get an upload session on a catalog resource effect: read questions: - What status and stats does a direct catalog resource upload session report? - Can I tell whether uploading is done for one session on a catalog resource? instructions: - text: Get upload session {session} directly on catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Show status of resource {resource}'s custom data session {session}. slots: resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].delete update: x-apievangelist-phrasing: intent: Delete an upload session on a catalog resource effect: destructive questions: - Can I delete a custom data session opened directly on a catalog resource? - What removes one of a catalog resource's own upload sessions? instructions: - text: Delete upload session {session} directly on catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Remove resource {resource}'s custom data session {session}. slots: resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}'].patch update: x-apievangelist-phrasing: intent: Update an upload session on a catalog resource effect: write questions: - How do I mark a catalog resource's own upload session as done? - Can I change the reference ID on a direct catalog resource session? instructions: - text: 'Mark session {session} directly on catalog resource {resource} as done: {isUploadDone}.' slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id isUploadDone: requestBody.isUploadDone - text: Set reference {referenceId} on resource {resource}'s custom data session {session}. slots: referenceId: requestBody.referenceId resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files'].get update: x-apievangelist-phrasing: intent: List files in a catalog resource upload session effect: read questions: - Which files have been uploaded to a session directly on a catalog resource? - Can I page through the files of a catalog resource's own session? instructions: - text: List files in session {session} directly on catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Show files uploaded to resource {resource}'s custom data session {session}. slots: resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}'].get update: x-apievangelist-phrasing: intent: Get one file in a catalog resource upload session effect: read questions: - How do I look up one file uploaded directly to a catalog resource session? - What record is kept for a single file in a catalog resource's own session? instructions: - text: Get file {file} in session {session} directly on catalog resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Fetch file record {file} from resource {resource}'s custom data session {session}. slots: file: path.customDataProvidedResourceFile-id resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].get update: x-apievangelist-phrasing: intent: Download file content from a catalog resource session effect: read questions: - Can I download the bytes of a file uploaded directly to a catalog resource session? - Where is the raw content of a file in a catalog resource's own session? instructions: - text: Download content of file {file} in session {session} directly on catalog resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Pull raw bytes of file {file} from resource {resource}'s custom data session {session}. slots: file: path.customDataProvidedResourceFile-id resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].put update: x-apievangelist-phrasing: intent: Replace file content in a catalog resource session effect: write questions: - How do I overwrite a file's bytes in a catalog resource's own upload session? - Can I replace the content of a file uploaded directly to a catalog resource? instructions: - text: Replace content of file {file} in session {session} directly on catalog resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Overwrite bytes of file {file} in resource {resource}'s custom data session {session}. slots: file: path.customDataProvidedResourceFile-id resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/{customDataProvidedResourceFile-id}/$value'].delete update: x-apievangelist-phrasing: intent: Delete file content in a catalog resource session effect: destructive questions: - Can I clear a file's content in a catalog resource's own upload session? - What wipes the bytes of a file uploaded directly to a catalog resource? instructions: - text: Delete content of file {file} in session {session} directly on catalog resource {resource}. slots: file: path.customDataProvidedResourceFile-id session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Wipe bytes of file {file} in resource {resource}'s custom data session {session}. slots: file: path.customDataProvidedResourceFile-id resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/files/$count'].get update: x-apievangelist-phrasing: intent: Count files in a catalog resource upload session effect: read questions: - How many files are in a session opened directly on a catalog resource? - Is there a file count for a catalog resource's own upload session? instructions: - text: Count files in session {session} directly on catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Tally files in resource {resource}'s custom data session {session}. slots: resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/{customDataProvidedResourceUploadSession-id}/microsoft.graph.uploadFile'].post update: x-apievangelist-phrasing: intent: Upload a file to a catalog resource session effect: write questions: - How do I upload a custom data file directly to a catalog resource session? - Can I add a file to a catalog resource's open upload session? instructions: - text: Upload a file to session {session} directly on catalog resource {resource}. slots: session: path.customDataProvidedResourceUploadSession-id resource: path.accessPackageResource-id - text: Send a file into resource {resource}'s custom data session {session}. slots: resource: path.accessPackageResource-id session: path.customDataProvidedResourceUploadSession-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/{accessPackageResource-id}/uploadSessions/$count'].get update: x-apievangelist-phrasing: intent: Count upload sessions on a catalog resource effect: read questions: - How many upload sessions have been opened directly on a catalog resource? - Can I count a catalog resource's own custom data sessions? instructions: - text: Count upload sessions directly on catalog resource {resource}. slots: resource: path.accessPackageResource-id - text: Tell me how many custom data sessions resource {resource} has. slots: resource: path.accessPackageResource-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/resources/$count'].get update: x-apievangelist-phrasing: intent: Count catalog resources effect: read questions: - How many resources are registered across my access package catalogs? - Can I get a total count of entitlement management resources? instructions: - text: Count all catalog resources. - text: Tell me how many resources entitlement management tracks. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/settings'].get update: x-apievangelist-phrasing: intent: Get entitlement management settings effect: read questions: - What happens to external users in Microsoft Entra entitlement management when their last access package assignment ends? - Can I see how long blocked external users are kept before deletion? instructions: - text: Get the entitlement management settings. - text: Show the current external user lifecycle action. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/settings'].delete update: x-apievangelist-phrasing: intent: Delete entitlement management settings effect: destructive questions: - Can I remove the entitlement management settings object? - What resets tenant-wide entitlement management settings by deleting them? instructions: - text: Delete the entitlement management settings. - text: Remove tenant-wide entitlement management settings. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/settings'].patch update: x-apievangelist-phrasing: intent: Update entitlement management settings effect: write questions: - How do I make external users get blocked and deleted after they lose all access packages? - Can I change how many days a blocked external user waits before deletion? instructions: - text: Set the external user lifecycle action to {externalUserLifecycleAction}. slots: externalUserLifecycleAction: requestBody.externalUserLifecycleAction - text: Delete blocked external users after {durationUntilExternalUserDeletedAfterBlocked}. slots: durationUntilExternalUserDeletedAfterBlocked: requestBody.durationUntilExternalUserDeletedAfterBlocked method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects'].get update: x-apievangelist-phrasing: intent: List access package subjects effect: read questions: - Which external users are tracked as access package subjects? - Can I filter access package subjects by email or subject type? instructions: - text: List all access package subjects. - text: Show access package subjects whose lifecycle is governed. method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects'].post update: x-apievangelist-phrasing: intent: Add an access package subject effect: write questions: - How do I register an external user as an access package subject? - Can I create a subject with just an email and display name? instructions: - text: Create an access package subject for {email} named {displayName}. slots: email: requestBody.email displayName: requestBody.displayName - text: Add subject {principalName} with subject type {subjectType}. slots: principalName: requestBody.principalName subjectType: requestBody.subjectType method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects/{accessPackageSubject-id}'].get update: x-apievangelist-phrasing: intent: Get an access package subject by ID effect: read questions: - What does one access package subject record contain? - Can I look up a subject's lifecycle and principal name by its ID? instructions: - text: Get access package subject {subject}. slots: subject: path.accessPackageSubject-id - text: Show email and lifecycle for subject {subject}. slots: subject: path.accessPackageSubject-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects/{accessPackageSubject-id}'].delete update: x-apievangelist-phrasing: intent: Delete an access package subject by ID effect: destructive questions: - Can I remove an access package subject using its subject ID? - What deletes a tracked external user subject record? instructions: - text: Delete access package subject {subject}. slots: subject: path.accessPackageSubject-id - text: Remove subject record {subject}. slots: subject: path.accessPackageSubject-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects/{accessPackageSubject-id}'].patch update: x-apievangelist-phrasing: intent: Update an access package subject's lifecycle effect: write questions: - How do I change whether an external user subject is governed or not? - Can I update a subject's lifecycle using its subject ID? instructions: - text: Set the lifecycle of subject {subject} to {subjectLifecycle}. slots: subject: path.accessPackageSubject-id subjectLifecycle: requestBody.subjectLifecycle - text: Update subject {subject}'s display name to {displayName}. slots: subject: path.accessPackageSubject-id displayName: requestBody.displayName method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects/{accessPackageSubject-id}/connectedOrganization'].get update: x-apievangelist-phrasing: intent: Get a subject's connected organization effect: read questions: - Which connected organization does an external subject come from? - Can I see the partner organization tied to one access package subject? instructions: - text: Get the connected organization of subject {subject}. slots: subject: path.accessPackageSubject-id - text: Show which partner organization subject {subject} belongs to. slots: subject: path.accessPackageSubject-id method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects(objectId=\'{objectId}\')'].get update: x-apievangelist-phrasing: intent: Get an access package subject by object ID effect: read questions: - Can I look up an access package subject by the user's directory object ID? - How do I find a subject record when I only know the Entra object ID? instructions: - text: Get the access package subject with object ID {objectId}. slots: objectId: path.objectId - text: Find the subject for directory user {objectId}. slots: objectId: path.objectId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects(objectId=\'{objectId}\')'].delete update: x-apievangelist-phrasing: intent: Delete an access package subject by object ID effect: destructive questions: - Can I delete a subject using the user's directory object ID instead of the subject ID? - What removes a subject record addressed by Entra object ID? instructions: - text: Delete the access package subject with object ID {objectId}. slots: objectId: path.objectId - text: Remove the subject for directory user {objectId}. slots: objectId: path.objectId method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects(objectId=\'{objectId}\')'].patch update: x-apievangelist-phrasing: intent: Update a subject's lifecycle by object ID effect: write questions: - How do I change a subject's lifecycle when I only have the user's object ID? - Can I update an external subject addressed by directory object ID? instructions: - text: Set the lifecycle of the subject with object ID {objectId} to {subjectLifecycle}. slots: objectId: path.objectId subjectLifecycle: requestBody.subjectLifecycle - text: Update the subject for directory user {objectId} with email {email}. slots: objectId: path.objectId email: requestBody.email method: generated generated: '2026-10-01' - target: $.paths['/identityGovernance/entitlementManagement/subjects/$count'].get update: x-apievangelist-phrasing: intent: Count access package subjects effect: read questions: - How many access package subjects exist in my tenant? - Can I get a total count of tracked external user subjects? instructions: - text: Count all access package subjects. - text: Tell me how many access package subjects there are. method: generated generated: '2026-10-01'