# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for CData Connect AI Management Service Accounts API version: 1.0.0 extends: openapi/cdata-service-accounts-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/service-accounts'].get update: x-apievangelist-phrasing: intent: List the organization's service accounts effect: read questions: - Which machine identities, like CI/CD service accounts, exist in our Connect AI organization? - Can I list only the service accounts that are deactivated? - Which service accounts hold a particular role? instructions: - text: List all service accounts in the organization. - text: Show service accounts with status {status}. slots: status: query.status - text: List the service accounts directly assigned role {role_id}, {limit} per page. slots: role_id: query.role_id limit: query.limit method: generated generated: '2026-09-26' - target: $.paths['/service-accounts'].post update: x-apievangelist-phrasing: intent: Create a service account for automation effect: write questions: - How do I create a machine identity for my Terraform or CI/CD pipeline? - Will creating a service account twice with the same external Id make a duplicate? - Where do I get the OAuth client Id for client credentials authentication? instructions: - text: Create a service account named {name}. slots: name: requestBody.name - text: Create service account {name} described as {description} with idempotency key {external_id}. slots: name: requestBody.name description: requestBody.description external_id: requestBody.external_id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}'].get update: x-apievangelist-phrasing: intent: Get one service account and its permissions effect: read questions: - How do I look up a single service account's details and direct permissions? - What status and settings does a given service account currently have? instructions: - text: Get service account {id}. slots: id: path.id - text: Show me the details of machine identity {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}'].delete update: x-apievangelist-phrasing: intent: Deprovision a service account effect: destructive questions: - What happens to a service account's tokens and roles when I delete it? - How do I permanently deprovision a machine identity we no longer use? instructions: - text: Delete service account {id} and revoke all its tokens. slots: id: path.id - text: Permanently deprovision the machine identity {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}'].patch update: x-apievangelist-phrasing: intent: Rename or deactivate a service account effect: write questions: - Does deactivating a service account revoke its personal access tokens right away? - Can I rename a service account without touching its other fields? instructions: - text: Rename service account {id} to {name}. slots: id: path.id name: requestBody.name - text: Set the status of service account {id} to {status}. slots: id: path.id status: requestBody.status - text: Change the description of service account {id} to {description}. slots: id: path.id description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/roles'].get update: x-apievangelist-phrasing: intent: List roles held by a service account effect: read questions: - Which roles does a service account have across the organization, and where did each come from? - Is a service account an admin, and was it granted directly? instructions: - text: List all roles assigned to service account {id}. slots: id: path.id - text: Show every role grant and its provenance for machine identity {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/roles'].post update: x-apievangelist-phrasing: intent: Grant the account-wide admin role to a service account effect: write questions: - How do I make a service account an organization-wide admin? - Which role can be granted to a service account at the account level rather than per workspace? instructions: - text: Grant account-wide role {role_id} to service account {id}. slots: role_id: requestBody.role_id id: path.id - text: Make service account {id} an organization admin using role {role_id}. slots: id: path.id role_id: requestBody.role_id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/roles/{role_id}'].delete update: x-apievangelist-phrasing: intent: Remove an account-level role from a service account effect: destructive questions: - How do I take the admin role away from a service account? - Can I remove a role a service account got through a group? instructions: - text: Remove account-level role {role_id} from service account {id}. slots: role_id: path.role_id id: path.id - text: Revoke the org-wide admin role {role_id} held directly by machine identity {id}. slots: role_id: path.role_id id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/permissions'].get update: x-apievangelist-phrasing: intent: List a service account's direct permissions effect: read questions: - Which connections can a service account access through direct permissions? - What resource-level permissions were granted straight to a service account? instructions: - text: List the direct permissions of service account {id}. slots: id: path.id - text: Show which connections machine identity {id} has direct access to. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/permissions'].post update: x-apievangelist-phrasing: intent: Give a service account access to a connection effect: write questions: - How do I let a service account query one specific connection? - Can I restrict a service account to particular operations on a connection? instructions: - text: Give service account {id} {operations} access to connection {resource} as a {type} permission. slots: id: path.id operations: requestBody.operations resource: requestBody.resource type: requestBody.type - text: Grant machine identity {id} permission of type {type} to perform {operations} on {resource}. slots: id: path.id type: requestBody.type operations: requestBody.operations resource: requestBody.resource method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/permissions/{permission_id}'].delete update: x-apievangelist-phrasing: intent: Revoke a direct permission from a service account effect: destructive questions: - How do I cut off a service account's access to one connection without deleting it? - Can I revoke a single direct permission from a machine identity? instructions: - text: Remove permission {permission_id} from service account {id}. slots: permission_id: path.permission_id id: path.id - text: Revoke direct permission {permission_id} held by machine identity {id}. slots: permission_id: path.permission_id id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/workspaces/{workspace_id}/roles'].get update: x-apievangelist-phrasing: intent: List a service account's roles in one workspace effect: read questions: - Which roles does a service account hold inside a particular workspace? - Is a service account a workspace admin in a given workspace? instructions: - text: List the roles service account {id} holds in workspace {workspace_id}. slots: id: path.id workspace_id: path.workspace_id - text: Show workspace-scoped role grants for machine identity {id} in {workspace_id}. slots: id: path.id workspace_id: path.workspace_id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/workspaces/{workspace_id}/roles'].post update: x-apievangelist-phrasing: intent: Grant a workspace role to a service account effect: write questions: - How do I make a service account a workspace_admin in one workspace? - Can I assign a custom access role to a service account for a single workspace? instructions: - text: Grant role {role_id} to service account {id} in workspace {workspace_id}. slots: role_id: requestBody.role_id id: path.id workspace_id: path.workspace_id - text: Make machine identity {id} a workspace admin of {workspace_id} with role {role_id}. slots: id: path.id workspace_id: path.workspace_id role_id: requestBody.role_id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/workspaces/{workspace_id}/roles/{role_id}'].delete update: x-apievangelist-phrasing: intent: Remove a workspace role from a service account effect: destructive questions: - How do I take a workspace role away from a service account in one workspace? - Can I strip workspace admin rights from a machine identity without affecting other workspaces? instructions: - text: Remove role {role_id} from service account {id} in workspace {workspace_id}. slots: role_id: path.role_id id: path.id workspace_id: path.workspace_id - text: Revoke workspace {workspace_id} role {role_id} from machine identity {id}. slots: workspace_id: path.workspace_id role_id: path.role_id id: path.id method: generated generated: '2026-09-26'