# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Cloudera Service Iam API version: 1.0.0 extends: openapi/cloudera-iam-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 79 - target: $.paths['/iam/getUser'].post update: x-apievangelist-phrasing: intent: Look up a CDP user's details effect: read questions: - How can I see the details of one user in my CDP account? - Which CDP user does my current access key belong to? instructions: - text: Show me the CDP user profile for {userId}. slots: userId: requestBody.userId - text: Tell me which CDP user my access key is authenticated as. method: generated generated: '2026-10-01' - target: $.paths['/iam/listUsers'].post update: x-apievangelist-phrasing: intent: List users in the CDP account effect: read questions: - Can I get a list of every human user in my Cloudera CDP account? - Is the CDP user listing paginated with a page size? instructions: - text: List all users in my CDP account. - text: List the CDP users {userIds}, {pageSize} per page. slots: userIds: requestBody.userIds pageSize: requestBody.pageSize method: generated generated: '2026-10-01' - target: $.paths['/iam/createUser'].post update: x-apievangelist-phrasing: intent: Create a CDP user effect: write questions: - How do I add a new person as a user in CDP with their email and identity provider ID? - Can I put a new CDP user into groups at the moment I create them? instructions: - text: Create a CDP user with email {email} and identity provider user ID {identityProviderUserId}. slots: email: requestBody.email identityProviderUserId: requestBody.identityProviderUserId - text: Create CDP user {firstName} {lastName} ({email}, IdP ID {identityProviderUserId}) and add them to groups {groups}. slots: firstName: requestBody.firstName lastName: requestBody.lastName email: requestBody.email identityProviderUserId: requestBody.identityProviderUserId groups: requestBody.groups method: generated generated: '2026-10-01' - target: $.paths['/iam/updateUser'].post update: x-apievangelist-phrasing: intent: Activate or deactivate a CDP user effect: write questions: - Can I deactivate a CDP user without deleting them? - What happens if I send a user update with no fields changed? instructions: - text: Deactivate CDP user {user} by setting active to {active}. slots: user: requestBody.user active: requestBody.active - text: Reactivate the CDP user {user}. slots: user: requestBody.user method: generated generated: '2026-10-01' - target: $.paths['/iam/deleteUser'].post update: x-apievangelist-phrasing: intent: Delete a CDP user and their access effect: destructive questions: - What gets removed when I delete a human user from CDP? - Does deleting a CDP user also remove their access keys and group memberships? instructions: - text: Delete CDP user {userId} along with their access keys and role assignments. slots: userId: requestBody.userId - text: Permanently remove the person {userId} from my CDP account. slots: userId: requestBody.userId method: generated generated: '2026-10-01' - target: $.paths['/iam/createUserAccessKey'].post update: x-apievangelist-phrasing: intent: Create an API access key for a user effect: write questions: - How do I generate a CDP API access key for a human user? - Can I choose the key type when creating an access key for a user? instructions: - text: Create a new API access key for user {user}. slots: user: requestBody.user - text: Generate a {type} access key for CDP user {user}. slots: type: requestBody.type user: requestBody.user method: generated generated: '2026-10-01' - target: $.paths['/iam/createMachineUserAccessKey'].post update: x-apievangelist-phrasing: intent: Create an access key for a machine user effect: write questions: - How do I give a CDP machine user an API key for automation? - Which key types can I pick when creating a machine user's access key? instructions: - text: Create an access key for machine user {machineUserName}. slots: machineUserName: requestBody.machineUserName - text: Generate a {type} access key for the service account {machineUserName}. slots: type: requestBody.type machineUserName: requestBody.machineUserName method: generated generated: '2026-10-01' - target: $.paths['/iam/deleteAccessKey'].post update: x-apievangelist-phrasing: intent: Delete an API access key effect: destructive questions: - How do I permanently delete a CDP access key that leaked? - Is deleting an access key different from just disabling it? instructions: - text: Delete access key {accessKeyId}. slots: accessKeyId: requestBody.accessKeyId - text: Permanently remove the CDP API key {accessKeyId}. slots: accessKeyId: requestBody.accessKeyId method: generated generated: '2026-10-01' - target: $.paths['/iam/updateAccessKey'].post update: x-apievangelist-phrasing: intent: Enable or disable an access key effect: write questions: - Can I temporarily disable a CDP access key instead of deleting it? - How do I turn an inactive access key back on? instructions: - text: Set the status of access key {accessKeyId} to {status}. slots: accessKeyId: requestBody.accessKeyId status: requestBody.status - text: Disable access key {accessKeyId} for now. slots: accessKeyId: requestBody.accessKeyId method: generated generated: '2026-10-01' - target: $.paths['/iam/getAccessKey'].post update: x-apievangelist-phrasing: intent: Look up an access key's details effect: read questions: - Which actor owns a given CDP access key and is it active? - Can I see details of the access key I'm calling the API with? instructions: - text: Show details for access key {accessKeyId}. slots: accessKeyId: requestBody.accessKeyId - text: Describe the access key I'm currently using. method: generated generated: '2026-10-01' - target: $.paths['/iam/listAccessKeys'].post update: x-apievangelist-phrasing: intent: List access keys in the account effect: read questions: - What API access keys exist across my CDP account? - Can I page through access keys a few at a time? instructions: - text: List all CDP access keys. - text: List access keys {accessKeyIds}. slots: accessKeyIds: requestBody.accessKeyIds method: generated generated: '2026-10-01' - target: $.paths['/iam/listRoles'].post update: x-apievangelist-phrasing: intent: List the account-level roles available effect: read questions: - What account-wide roles can I grant in CDP? - Which policies do CDP roles carry? instructions: - text: List every account role available in CDP. - text: Show the roles named {roleNames}. slots: roleNames: requestBody.roleNames method: generated generated: '2026-10-01' - target: $.paths['/iam/listResourceRoles'].post update: x-apievangelist-phrasing: intent: List available resource roles effect: read questions: - Which resource roles exist for granting rights over specific CDP resources? - Can I look up a resource role's CRN by name? instructions: - text: List all resource roles available in CDP. - text: Show the resource roles {resourceRoleNames}. slots: resourceRoleNames: requestBody.resourceRoleNames method: generated generated: '2026-10-01' - target: $.paths['/iam/setAccountMessages'].post update: x-apievangelist-phrasing: intent: Set the account's contact-your-admin message effect: write questions: - Can I customize the 'contact your administrator' message users see in CDP? - Where do I set the help text shown to users who lack access? instructions: - text: Set the contact-your-administrator message to {contactYourAdministratorMessage}. slots: contactYourAdministratorMessage: requestBody.contactYourAdministratorMessage - text: Update the account message users see when they need admin help to {contactYourAdministratorMessage}. slots: contactYourAdministratorMessage: requestBody.contactYourAdministratorMessage method: generated generated: '2026-10-01' - target: $.paths['/iam/getAccountMessages'].post update: x-apievangelist-phrasing: intent: Get the account's custom messages effect: read questions: - What admin contact message is currently configured for my CDP account? - Can I read back the custom account messages users see? instructions: - text: Show the current account messages. - text: Get the contact-your-administrator text set on my CDP account. method: generated generated: '2026-10-01' - target: $.paths['/iam/assignUserRole'].post update: x-apievangelist-phrasing: intent: Grant an account role to a user effect: write questions: - How do I give a human user an account-level role like PowerUser? - What happens if the user already has that role? instructions: - text: Assign role {role} to user {user}. slots: role: requestBody.role user: requestBody.user - text: Grant {user} the account role {role}. slots: user: requestBody.user role: requestBody.role method: generated generated: '2026-10-01' - target: $.paths['/iam/unassignUserRole'].post update: x-apievangelist-phrasing: intent: Remove an account role from a user effect: destructive questions: - How can I take an account role away from a human user? - Will unassigning fail if the user doesn't have the role? instructions: - text: Unassign role {role} from user {user}. slots: role: requestBody.role user: requestBody.user - text: Revoke the account role {role} held by {user}. slots: role: requestBody.role user: requestBody.user method: generated generated: '2026-10-01' - target: $.paths['/iam/assignUserResourceRole'].post update: x-apievangelist-phrasing: intent: Grant a user a role on a specific resource effect: write questions: - How do I give a user rights over a single environment rather than the whole account? - What CRNs do I need to grant a resource role to a person? instructions: - text: Assign resource role {resourceRoleCrn} on {resourceCrn} to user {user}. slots: resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn user: requestBody.user - text: Give user {user} the {resourceRoleCrn} resource role over resource {resourceCrn}. slots: user: requestBody.user resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/unassignUserResourceRole'].post update: x-apievangelist-phrasing: intent: Remove a user's role on a specific resource effect: destructive questions: - How do I revoke a person's access to one specific CDP resource? - Does removing a user's resource role fail if it wasn't assigned? instructions: - text: Unassign resource role {resourceRoleCrn} on {resourceCrn} from user {user}. slots: resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn user: requestBody.user - text: Revoke user {user}'s {resourceRoleCrn} rights over {resourceCrn}. slots: user: requestBody.user resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/listUserAssignedRoles'].post update: x-apievangelist-phrasing: intent: List a user's account roles effect: read questions: - What account roles does a particular human user hold? - Which account roles do I have myself? instructions: - text: List the account roles assigned to user {user}. slots: user: requestBody.user - text: Show my own assigned account roles. method: generated generated: '2026-10-01' - target: $.paths['/iam/listUserAssignedResourceRoles'].post update: x-apievangelist-phrasing: intent: List a user's resource role assignments effect: read questions: - Which resources does a user have resource roles on? - Can I audit a person's per-resource permissions? instructions: - text: List the resource roles assigned to user {user}. slots: user: requestBody.user - text: Show my own resource role assignments. method: generated generated: '2026-10-01' - target: $.paths['/iam/assignMachineUserRole'].post update: x-apievangelist-phrasing: intent: Grant an account role to a machine user effect: write questions: - How do I give a service account (machine user) an account-level role? - Will it error if the machine user already has the role? instructions: - text: Assign role {role} to machine user {machineUserName}. slots: role: requestBody.role machineUserName: requestBody.machineUserName - text: Grant the service account {machineUserName} the account role {role}. slots: machineUserName: requestBody.machineUserName role: requestBody.role method: generated generated: '2026-10-01' - target: $.paths['/iam/unassignMachineUserRole'].post update: x-apievangelist-phrasing: intent: Remove an account role from a machine user effect: destructive questions: - Can I strip an account role from a machine user? - What if the machine user doesn't actually hold the role I'm removing? instructions: - text: Unassign role {role} from machine user {machineUserName}. slots: role: requestBody.role machineUserName: requestBody.machineUserName - text: Revoke account role {role} from the service account {machineUserName}. slots: role: requestBody.role machineUserName: requestBody.machineUserName method: generated generated: '2026-10-01' - target: $.paths['/iam/assignMachineUserResourceRole'].post update: x-apievangelist-phrasing: intent: Grant a machine user a role on a resource effect: write questions: - How do I scope a machine user's permissions to a single CDP resource? - Which CRNs are required to give a service account a resource role? instructions: - text: Grant machine account {machineUserName} resource-scoped role {resourceRoleCrn} over {resourceCrn}. slots: resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn machineUserName: requestBody.machineUserName - text: Let service account {machineUserName} act as {resourceRoleCrn} over {resourceCrn}. slots: machineUserName: requestBody.machineUserName resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/unassignMachineUserResourceRole'].post update: x-apievangelist-phrasing: intent: Remove a machine user's role on a resource effect: destructive questions: - How do I revoke a machine user's rights on one specific resource? - Does removing a service account's resource role fail when it isn't assigned? instructions: - text: Strip resource-scoped role {resourceRoleCrn} on {resourceCrn} from machine account {machineUserName}. slots: resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn machineUserName: requestBody.machineUserName - text: Revoke service account {machineUserName}'s {resourceRoleCrn} rights on {resourceCrn}. slots: machineUserName: requestBody.machineUserName resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/listMachineUserAssignedRoles'].post update: x-apievangelist-phrasing: intent: List a machine user's account roles effect: read questions: - What account roles has a given machine user been granted? - Can I audit the account-level roles of a service account? instructions: - text: Enumerate the account-wide roles carried by machine account {machineUserName}. slots: machineUserName: requestBody.machineUserName - text: Show which account roles the service account {machineUserName} holds. slots: machineUserName: requestBody.machineUserName method: generated generated: '2026-10-01' - target: $.paths['/iam/listMachineUserAssignedResourceRoles'].post update: x-apievangelist-phrasing: intent: List a machine user's resource roles effect: read questions: - Which resources does a machine user hold resource roles on? - Can I review a service account's per-resource permissions? instructions: - text: Audit resource-scoped grants for machine account {machineUserName}. slots: machineUserName: requestBody.machineUserName - text: Show the per-resource grants for service account {machineUserName}. slots: machineUserName: requestBody.machineUserName method: generated generated: '2026-10-01' - target: $.paths['/iam/listResourceAssignees'].post update: x-apievangelist-phrasing: intent: List who has roles on a resource effect: read questions: - Who has access to a particular CDP environment or resource, and with which role? - Can I list every assignee of a resource along with their resource roles? instructions: - text: List everyone assigned resource roles on {resourceCrn}. slots: resourceCrn: requestBody.resourceCrn - text: Show the assignees and their roles for resource {resourceCrn}, {pageSize} at a time. slots: resourceCrn: requestBody.resourceCrn pageSize: requestBody.pageSize method: generated generated: '2026-10-01' - target: $.paths['/iam/createMachineUser'].post update: x-apievangelist-phrasing: intent: Create a machine user for API access effect: write questions: - How do I create a service account in CDP for automation scripts? - Can a machine user log in to the CDP console? instructions: - text: Create a machine user named {machineUserName}. slots: machineUserName: requestBody.machineUserName - text: Set up a new CDP service account called {machineUserName} for my pipelines. slots: machineUserName: requestBody.machineUserName method: generated generated: '2026-10-01' - target: $.paths['/iam/listMachineUsers'].post update: x-apievangelist-phrasing: intent: List machine users in the account effect: read questions: - What service accounts (machine users) exist in my CDP account? - Can I look up specific machine users by name? instructions: - text: List all machine users in my account. - text: Show the machine users {machineUserNames}. slots: machineUserNames: requestBody.machineUserNames method: generated generated: '2026-10-01' - target: $.paths['/iam/deleteMachineUser'].post update: x-apievangelist-phrasing: intent: Delete a machine user effect: destructive questions: - What gets cleaned up when I delete a CDP machine user? - Does deleting a service account remove its access keys and group memberships? instructions: - text: Delete machine user {machineUserName}. slots: machineUserName: requestBody.machineUserName - text: Remove the service account {machineUserName} and all its access keys. slots: machineUserName: requestBody.machineUserName method: generated generated: '2026-10-01' - target: $.paths['/iam/createSamlProvider'].post update: x-apievangelist-phrasing: intent: Register a SAML identity provider effect: write questions: - How do I connect my SAML identity provider to CDP for single sign-on? - Can I enable SCIM provisioning when adding a SAML provider? instructions: - text: Create SAML provider {samlProviderName} with metadata {samlMetadataDocument}. slots: samlProviderName: requestBody.samlProviderName samlMetadataDocument: requestBody.samlMetadataDocument - text: Add SAML provider {samlProviderName} with SCIM set to {enableScim} and group sync on login {syncGroupsOnLogin}. slots: samlProviderName: requestBody.samlProviderName enableScim: requestBody.enableScim syncGroupsOnLogin: requestBody.syncGroupsOnLogin method: generated generated: '2026-10-01' - target: $.paths['/iam/deleteSamlProvider'].post update: x-apievangelist-phrasing: intent: Delete a SAML identity provider effect: destructive questions: - How do I remove a SAML identity provider from my CDP account? - Can I disconnect an old SSO provider I no longer use? instructions: - text: Delete SAML provider {samlProviderName}. slots: samlProviderName: requestBody.samlProviderName - text: Remove the {samlProviderName} SSO connection from CDP. slots: samlProviderName: requestBody.samlProviderName method: generated generated: '2026-10-01' - target: $.paths['/iam/listSamlProviders'].post update: x-apievangelist-phrasing: intent: List SAML identity providers effect: read questions: - Which SAML identity providers are configured in my CDP account? - Can I page through SAML providers by name? instructions: - text: List all SAML providers in my account. - text: List SAML providers named {samlProviderNames}. slots: samlProviderNames: requestBody.samlProviderNames method: generated generated: '2026-10-01' - target: $.paths['/iam/describeSamlProvider'].post update: x-apievangelist-phrasing: intent: Show one SAML provider's configuration effect: read questions: - What settings does a specific SAML provider have, like SCIM or group sync? - Can I view the full configuration of one SSO provider? instructions: - text: Describe SAML provider {samlProviderName}. slots: samlProviderName: requestBody.samlProviderName - text: Show the configuration of the {samlProviderName} SSO connection. slots: samlProviderName: requestBody.samlProviderName method: generated generated: '2026-10-01' - target: $.paths['/iam/updateSamlProvider'].post update: x-apievangelist-phrasing: intent: Update a SAML provider's settings effect: write questions: - How do I upload new SAML metadata for an existing identity provider? - Can I switch on SCIM for a SAML provider that's already set up? instructions: - text: Update SAML provider {samlProviderName} with new metadata {samlMetadataDocument}. slots: samlProviderName: requestBody.samlProviderName samlMetadataDocument: requestBody.samlMetadataDocument - text: Turn workload usernames from email to {generateWorkloadUsernameByEmail} on existing SAML provider {samlProviderName}. slots: generateWorkloadUsernameByEmail: requestBody.generateWorkloadUsernameByEmail samlProviderName: requestBody.samlProviderName method: generated generated: '2026-10-01' - target: $.paths['/iam/enableClouderaSSOLogin'].post update: x-apievangelist-phrasing: intent: Enable Cloudera SSO login for the account effect: write questions: - How do I allow all users to log in with Cloudera SSO? - Is turning on Cloudera SSO safe if it's already enabled? instructions: - text: Enable Cloudera SSO interactive login for my account. - text: Turn Cloudera SSO login back on for everyone. method: generated generated: '2026-10-01' - target: $.paths['/iam/disableClouderaSSOLogin'].post update: x-apievangelist-phrasing: intent: Disable Cloudera SSO login for non-admins effect: write questions: - Can I force users to log in through my own identity provider instead of Cloudera SSO? - Who can still use Cloudera SSO after it's disabled? instructions: - text: Disable Cloudera SSO login for my account. - text: Restrict Cloudera SSO so only account administrators can use it. method: generated generated: '2026-10-01' - target: $.paths['/iam/getAccount'].post update: x-apievangelist-phrasing: intent: Get CDP account information effect: read questions: - What account-level settings does my CDP tenant have? - Can I retrieve information about my CDP account itself? instructions: - text: Show my CDP account information. - text: Get the details of the current CDP account. method: generated generated: '2026-10-01' - target: $.paths['/iam/createGroup'].post update: x-apievangelist-phrasing: intent: Create a user group effect: write questions: - How do I create a group in CDP to manage roles for many users at once? - Can a group's membership sync from the identity provider on login? instructions: - text: Create a group called {groupName}. slots: groupName: requestBody.groupName - text: Create group {groupName} with sync-membership-on-login set to {syncMembershipOnUserLogin}. slots: groupName: requestBody.groupName syncMembershipOnUserLogin: requestBody.syncMembershipOnUserLogin method: generated generated: '2026-10-01' - target: $.paths['/iam/deleteGroup'].post update: x-apievangelist-phrasing: intent: Delete a user group effect: destructive questions: - How do I delete a CDP group I no longer need? - Can I remove an obsolete group from my account? instructions: - text: Delete group {groupName}. slots: groupName: requestBody.groupName - text: Remove the {groupName} group from CDP. slots: groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/listGroups'].post update: x-apievangelist-phrasing: intent: List groups in the account effect: read questions: - What groups exist in my CDP account? - Can I look up a few specific groups by name? instructions: - text: List all groups in my CDP account. - text: Show the groups {groupNames}. slots: groupNames: requestBody.groupNames method: generated generated: '2026-10-01' - target: $.paths['/iam/updateGroup'].post update: x-apievangelist-phrasing: intent: Change a group's membership sync setting effect: write questions: - Can I change whether an existing group syncs its members when users log in? - Is there a way to edit a group's settings after creating it? instructions: - text: Set sync-membership-on-login to {syncMembershipOnUserLogin} for existing group {groupName}. slots: syncMembershipOnUserLogin: requestBody.syncMembershipOnUserLogin groupName: requestBody.groupName - text: Update group {groupName} so login no longer syncs membership. slots: groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/addUserToGroup'].post update: x-apievangelist-phrasing: intent: Add a user to a group effect: write questions: - How do I put a human user into a CDP group? - Does adding someone to a group give them the group's roles? instructions: - text: Add user {userId} to group {groupName}. slots: userId: requestBody.userId groupName: requestBody.groupName - text: Make {userId} a member of the {groupName} group. slots: userId: requestBody.userId groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/addMachineUserToGroup'].post update: x-apievangelist-phrasing: intent: Add a machine user to a group effect: write questions: - Can a service account be a member of a CDP group? - How do I give a machine user a group's permissions? instructions: - text: Add machine user {machineUserName} to group {groupName}. slots: machineUserName: requestBody.machineUserName groupName: requestBody.groupName - text: Put the service account {machineUserName} into {groupName}. slots: machineUserName: requestBody.machineUserName groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/removeUserFromGroup'].post update: x-apievangelist-phrasing: intent: Remove a user from a group effect: destructive questions: - How do I take a person out of a CDP group? - Will removing a user from a group drop the roles they got through it? instructions: - text: Remove user {userId} from group {groupName}. slots: userId: requestBody.userId groupName: requestBody.groupName - text: Take {userId} out of the {groupName} group. slots: userId: requestBody.userId groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/removeMachineUserFromGroup'].post update: x-apievangelist-phrasing: intent: Remove a machine user from a group effect: destructive questions: - Can I pull a service account out of a group? - How do I stop a machine user inheriting a group's roles? instructions: - text: Remove machine user {machineUserName} from group {groupName}. slots: machineUserName: requestBody.machineUserName groupName: requestBody.groupName - text: Take the service account {machineUserName} out of {groupName}. slots: machineUserName: requestBody.machineUserName groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/listGroupMembers'].post update: x-apievangelist-phrasing: intent: List the members of a group effect: read questions: - Who belongs to a given CDP group? - Does the group member list include machine users too? instructions: - text: List the members of group {groupName}. slots: groupName: requestBody.groupName - text: Show everyone in {groupName}, {pageSize} per page. slots: groupName: requestBody.groupName pageSize: requestBody.pageSize method: generated generated: '2026-10-01' - target: $.paths['/iam/listGroupsForUser'].post update: x-apievangelist-phrasing: intent: List the groups a user belongs to effect: read questions: - Which groups is a particular person a member of? - Can I see all group memberships for one human user? instructions: - text: List the groups user {userId} belongs to. slots: userId: requestBody.userId - text: Show group memberships for {userId}. slots: userId: requestBody.userId method: generated generated: '2026-10-01' - target: $.paths['/iam/listGroupsForMachineUser'].post update: x-apievangelist-phrasing: intent: List the groups a machine user belongs to effect: read questions: - Which groups has a service account been added to? - Can I check a machine user's group memberships? instructions: - text: Find every group that machine account {machineUserName} is in. slots: machineUserName: requestBody.machineUserName - text: Show group memberships for the service account {machineUserName}. slots: machineUserName: requestBody.machineUserName method: generated generated: '2026-10-01' - target: $.paths['/iam/assignGroupRole'].post update: x-apievangelist-phrasing: intent: Grant an account role to a group effect: write questions: - How do I give every member of a group the same account role? - Will assigning fail if the group already has that role? instructions: - text: Assign role {role} to group {groupName}. slots: role: requestBody.role groupName: requestBody.groupName - text: Grant all members of {groupName} the account role {role}. slots: groupName: requestBody.groupName role: requestBody.role method: generated generated: '2026-10-01' - target: $.paths['/iam/unassignGroupRole'].post update: x-apievangelist-phrasing: intent: Remove an account role from a group effect: destructive questions: - Can I revoke an account role from an entire group at once? - What if the group doesn't currently have the role? instructions: - text: Unassign role {role} from group {groupName}. slots: role: requestBody.role groupName: requestBody.groupName - text: Revoke the {role} account role from everyone in {groupName}. slots: role: requestBody.role groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/assignGroupResourceRole'].post update: x-apievangelist-phrasing: intent: Grant a group a role on a resource effect: write questions: - How do I give a whole group access to one specific CDP environment? - Which CRNs do I need to assign a group a resource role? instructions: - text: Assign resource role {resourceRoleCrn} on {resourceCrn} to group {groupName}. slots: resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn groupName: requestBody.groupName - text: Let group {groupName} act as {resourceRoleCrn} over resource {resourceCrn}. slots: groupName: requestBody.groupName resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/unassignGroupResourceRole'].post update: x-apievangelist-phrasing: intent: Remove a group's role on a resource effect: destructive questions: - How can I revoke a group's rights on a single resource? - Does removing a group's resource role fail if it isn't assigned? instructions: - text: Unassign resource role {resourceRoleCrn} on {resourceCrn} from group {groupName}. slots: resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn groupName: requestBody.groupName - text: Revoke group {groupName}'s {resourceRoleCrn} rights on {resourceCrn}. slots: groupName: requestBody.groupName resourceRoleCrn: requestBody.resourceRoleCrn resourceCrn: requestBody.resourceCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/listGroupAssignedRoles'].post update: x-apievangelist-phrasing: intent: List a group's account roles effect: read questions: - What account roles are attached to a particular group? - Can I audit the account-level roles a group grants its members? instructions: - text: List the account roles assigned to group {groupName}. slots: groupName: requestBody.groupName - text: Show which account roles {groupName} holds. slots: groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/listGroupAssignedResourceRoles'].post update: x-apievangelist-phrasing: intent: List a group's resource role assignments effect: read questions: - Which resources does a group have resource roles on? - Can I review a group's per-resource permissions? instructions: - text: List the resource roles assigned to group {groupName}. slots: groupName: requestBody.groupName - text: Show the per-resource grants held by group {groupName}. slots: groupName: requestBody.groupName method: generated generated: '2026-10-01' - target: $.paths['/iam/setWorkloadPassword'].post update: x-apievangelist-phrasing: intent: Set an actor's workload password effect: write questions: - How do I set the password I use to log in to workload clusters in my environments? - Does a workload password apply to environments I get access to later? instructions: - text: Set my workload password to {password}. slots: password: requestBody.password - text: Set the workload password for actor {actorCrn} to {password}. slots: actorCrn: requestBody.actorCrn password: requestBody.password method: generated generated: '2026-10-01' - target: $.paths['/iam/unsetWorkloadPasswordMinLifetime'].post update: x-apievangelist-phrasing: intent: Clear an actor's workload password minimum lifetime effect: write questions: - Can I let a user change their workload password again before the minimum lifetime is up? - How do I remove the minimum lifetime date on someone's workload password? instructions: - text: Remove the workload password minimum lifetime for actor {actorCrn}. slots: actorCrn: requestBody.actorCrn - text: Clear the min-lifetime lock on {actorCrn}'s workload password. slots: actorCrn: requestBody.actorCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/setWorkloadPasswordPolicy'].post update: x-apievangelist-phrasing: intent: Set the account's workload password policy effect: write questions: - Can I make workload passwords expire across my CDP account? - Does a new workload password policy affect passwords already set? instructions: - text: Set the global workload password policy to {globalPasswordPolicy}. slots: globalPasswordPolicy: requestBody.globalPasswordPolicy - text: Apply workload password policy {machineUsersPasswordPolicy} to machine users. slots: machineUsersPasswordPolicy: requestBody.machineUsersPasswordPolicy method: generated generated: '2026-10-01' - target: $.paths['/iam/unsetWorkloadPasswordPolicy'].post update: x-apievangelist-phrasing: intent: Remove the account's workload password policy effect: write questions: - How do I go back to workload passwords that never expire? - Can I clear only the machine-user password policy and keep the global one? instructions: - text: Unset the global workload password policy. - text: Remove the machine users workload password policy by setting unset flag {unsetMachineUsersPasswordPolicy}. slots: unsetMachineUsersPasswordPolicy: requestBody.unsetMachineUsersPasswordPolicy method: generated generated: '2026-10-01' - target: $.paths['/iam/addSshPublicKey'].post update: x-apievangelist-phrasing: intent: Add an SSH public key for cluster access effect: write questions: - How do I upload my SSH public key so I can SSH into workload clusters? - Can I add an SSH key on behalf of another actor? instructions: - text: Add SSH public key {publicKey} to my account. slots: publicKey: requestBody.publicKey - text: Add SSH key {publicKey} for actor {actorCrn} described as {description}. slots: publicKey: requestBody.publicKey actorCrn: requestBody.actorCrn description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/iam/listSshPublicKeys'].post update: x-apievangelist-phrasing: intent: List an actor's SSH public keys effect: read questions: - Which SSH public keys are registered for me in CDP? - Can I see the SSH keys another user has uploaded? instructions: - text: List my SSH public keys. - text: List the SSH public keys for actor {actorCrn}. slots: actorCrn: requestBody.actorCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/describeSshPublicKey'].post update: x-apievangelist-phrasing: intent: Describe one SSH public key effect: read questions: - Can I look up an SSH key by its fingerprint? - What details are stored for a single SSH public key? instructions: - text: Describe the SSH key with fingerprint or CRN {crnOrFingerprint}. slots: crnOrFingerprint: requestBody.crnOrFingerprint - text: Show SSH key {crnOrFingerprint} belonging to {actorCrn}. slots: crnOrFingerprint: requestBody.crnOrFingerprint actorCrn: requestBody.actorCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/deleteSshPublicKey'].post update: x-apievangelist-phrasing: intent: Delete an SSH public key effect: destructive questions: - How do I remove an old SSH key so it can't reach workload clusters anymore? - Can I delete an SSH key by fingerprint? instructions: - text: Delete SSH key {crnOrFingerprint}. slots: crnOrFingerprint: requestBody.crnOrFingerprint - text: Remove SSH public key {crnOrFingerprint} from actor {actorCrn}. slots: crnOrFingerprint: requestBody.crnOrFingerprint actorCrn: requestBody.actorCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/updateLdapProvider'].post update: x-apievangelist-phrasing: intent: Update an LDAP identity provider effect: write questions: - How do I change the URL or search filters of an existing LDAP connection? - Can I rotate the bind password on an LDAP provider I already configured? instructions: - text: Update existing LDAP provider {ldapProviderName} to use URL {url}. slots: ldapProviderName: requestBody.ldapProviderName url: requestBody.url - text: Change the bind password on LDAP provider {ldapProviderName} to {bindPassword}. slots: ldapProviderName: requestBody.ldapProviderName bindPassword: requestBody.bindPassword method: generated generated: '2026-10-01' - target: $.paths['/iam/createLdapProvider'].post update: x-apievangelist-phrasing: intent: Create an LDAP identity provider effect: write questions: - How do I connect my LDAP directory to CDP for user authentication? - What search bases and filters are required to add a new LDAP provider? instructions: - text: Create a new LDAP provider {ldapProviderName} at {url} with user search base {userSearchBase} and group search base {groupSearchBase}. slots: ldapProviderName: requestBody.ldapProviderName url: requestBody.url userSearchBase: requestBody.userSearchBase groupSearchBase: requestBody.groupSearchBase - text: Add LDAP provider {ldapProviderName} mapping usernames from attribute {usernameMappingAttribute}. slots: ldapProviderName: requestBody.ldapProviderName usernameMappingAttribute: requestBody.usernameMappingAttribute method: generated generated: '2026-10-01' - target: $.paths['/iam/getDefaultIdentityProvider'].post update: x-apievangelist-phrasing: intent: Get the default identity provider effect: read questions: - Which identity provider does CDP use by default when it starts a login? - What is the CRN of my account's default IdP? instructions: - text: Show the default identity provider for my account. - text: Get the CRN of the IdP used for CDP-initiated logins. method: generated generated: '2026-10-01' - target: $.paths['/iam/setDefaultIdentityProvider'].post update: x-apievangelist-phrasing: intent: Set the default identity provider effect: write questions: - Can I change which identity provider CDP sends users to at login? - How do I make my new SAML provider the default for CDP-initiated logins? instructions: - text: Make {nameOrCrn} the default identity provider. slots: nameOrCrn: requestBody.nameOrCrn - text: Switch CDP-initiated logins to use identity provider {nameOrCrn}. slots: nameOrCrn: requestBody.nameOrCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/generateWorkloadAuthToken'].post update: x-apievangelist-phrasing: intent: Generate a token for workload APIs effect: write questions: - How do I get an auth token to call a workload API like Data Engineering jobs? - Can I leave group memberships out of a workload auth token? instructions: - text: Generate a workload auth token for {workloadName}. slots: workloadName: requestBody.workloadName - text: Generate a {workloadName} workload token for environment {environmentCrn}. slots: workloadName: requestBody.workloadName environmentCrn: requestBody.environmentCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/createScimAccessToken'].post update: x-apievangelist-phrasing: intent: Create a SCIM access token effect: write questions: - How do I create a token so my identity provider can push users to CDP over SCIM? - Can I set how many days a SCIM access token stays valid? instructions: - text: Create a SCIM access token for identity provider {identityProviderNameOrCrn} valid for {accessTokenLifetimeDays} days. slots: identityProviderNameOrCrn: requestBody.identityProviderNameOrCrn accessTokenLifetimeDays: requestBody.accessTokenLifetimeDays - text: Issue a new SCIM provisioning token for {identityProviderNameOrCrn} lasting {accessTokenLifetimeDays} days. slots: identityProviderNameOrCrn: requestBody.identityProviderNameOrCrn accessTokenLifetimeDays: requestBody.accessTokenLifetimeDays method: generated generated: '2026-10-01' - target: $.paths['/iam/listScimAccessTokens'].post update: x-apievangelist-phrasing: intent: List SCIM access tokens for an identity provider effect: read questions: - Which SCIM tokens are active for my identity provider? - Is SCIM token listing available on Cloudera for Government? instructions: - text: List SCIM access tokens for identity provider {identityProviderNameOrCrn}. slots: identityProviderNameOrCrn: requestBody.identityProviderNameOrCrn - text: Show all SCIM provisioning tokens issued for {identityProviderNameOrCrn}. slots: identityProviderNameOrCrn: requestBody.identityProviderNameOrCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/deleteScimAccessToken'].post update: x-apievangelist-phrasing: intent: Delete a SCIM access token effect: destructive questions: - How do I revoke a SCIM token that my IdP no longer uses? - Can I delete a SCIM access token by its ID? instructions: - text: Delete SCIM access token {accessTokenIdOrCrn}. slots: accessTokenIdOrCrn: requestBody.accessTokenIdOrCrn - text: Revoke the SCIM provisioning token {accessTokenIdOrCrn}. slots: accessTokenIdOrCrn: requestBody.accessTokenIdOrCrn method: generated generated: '2026-10-01' - target: $.paths['/iam/unlockUserInControlPlane'].post update: x-apievangelist-phrasing: intent: Unlock a locked-out user effect: write questions: - How do I unlock a human user who got locked out of the CDP control plane? - Is unlocking a user who isn't locked harmless? instructions: - text: Unlock user {user} in the control plane. slots: user: requestBody.user - text: Restore control plane access for locked-out user {user}. slots: user: requestBody.user method: generated generated: '2026-10-01' - target: $.paths['/iam/unlockMachineUserInControlPlane'].post update: x-apievangelist-phrasing: intent: Unlock a locked-out machine user effect: write questions: - Can I unlock a service account that's locked in the CDP control plane? - Which deployments support unlocking machine users? instructions: - text: Clear the control plane lockout on machine account {machineUser}. slots: machineUser: requestBody.machineUser - text: Restore control plane access for the service account {machineUser}. slots: machineUser: requestBody.machineUser method: generated generated: '2026-10-01' - target: $.paths['/iam/setSamlAuthnRequestSigningKey'].post update: x-apievangelist-phrasing: intent: Set the SAML AuthnRequest signing key effect: write questions: - How do I make CDP sign SAML authentication requests to my IdP? - Can I stage the next verification certificate for a signing key rotation? instructions: - text: Set the AuthnRequest signing key for SAML provider {samlProvider} to {authnRequestSigningKey}. slots: samlProvider: requestBody.samlProvider authnRequestSigningKey: requestBody.authnRequestSigningKey - text: Add next AuthnRequest verification certificate {nextAuthnRequestVerificationCertificate} to SAML provider {samlProvider}. slots: nextAuthnRequestVerificationCertificate: requestBody.nextAuthnRequestVerificationCertificate samlProvider: requestBody.samlProvider method: generated generated: '2026-10-01' - target: $.paths['/iam/migrateUsersToIdentityProvider'].post update: x-apievangelist-phrasing: intent: Move users to a different identity provider effect: write questions: - How do I migrate all users from LDAP authentication to SAML? - Do user IDs need to match in both identity providers for a migration? instructions: - text: Migrate all users from identity provider {originalProviderName} to {newProviderName}. slots: originalProviderName: requestBody.originalProviderName newProviderName: requestBody.newProviderName - text: Reassociate every user on {originalProviderName} with the {newProviderName} connector. slots: originalProviderName: requestBody.originalProviderName newProviderName: requestBody.newProviderName method: generated generated: '2026-10-01' - target: $.paths['/iam/setSamlResponseDecryptionKey'].post update: x-apievangelist-phrasing: intent: Set the SAML response encryption keys effect: write questions: - Can my IdP encrypt SAML responses sent to CDP? - Does setting a SAML decryption key replace the one stored before? instructions: - text: Set SAML response encryption certificate {samlResponseEncryptionCertificate} for provider {samlProvider}. slots: samlResponseEncryptionCertificate: requestBody.samlResponseEncryptionCertificate samlProvider: requestBody.samlProvider - text: Set the current SAML response decryption key on {samlProvider} to {currentSamlResponseDecryptionKey}. slots: samlProvider: requestBody.samlProvider currentSamlResponseDecryptionKey: requestBody.currentSamlResponseDecryptionKey method: generated generated: '2026-10-01' - target: $.paths['/iam/enableUserWorkloadPasswordChangedNotifications'].post update: x-apievangelist-phrasing: intent: Turn on workload password change emails effect: write questions: - Can users get an email whenever their workload password changes? - How do I enable password-changed notifications for the whole account? instructions: - text: Enable workload password changed email notifications. - text: Start emailing users when their workload password is changed. method: generated generated: '2026-10-01' - target: $.paths['/iam/disableUserWorkloadPasswordChangedNotifications'].post update: x-apievangelist-phrasing: intent: Turn off workload password change emails effect: write questions: - How do I stop CDP emailing users about workload password changes? - Can I silence password-changed notifications account-wide? instructions: - text: Disable workload password changed email notifications. - text: Stop sending users emails when their workload password changes. method: generated generated: '2026-10-01'