# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Dynatrace Account Management Policy Management API version: 1.0.0 extends: openapi/dynatrace-policy-management-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 27 - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies/validation'].post update: x-apievangelist-phrasing: intent: Validate a new policy draft (deprecated) effect: read questions: - Can I dry-run a brand-new IAM policy statement before creating it? - Is the separate new-policy validation endpoint being retired? instructions: - text: Validate a new policy {name} with statement {statement} and description {description} for {levelType} {level} using the deprecated check. slots: name: requestBody.name statement: requestBody.statementQuery description: requestBody.description levelType: path.level-type level: path.level-id - text: Dry-run creating policy {name} on {levelType} {level} with statement {statement}, description {description}. slots: name: requestBody.name levelType: path.level-type level: path.level-id statement: requestBody.statementQuery description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies/validation/{policy-uuid}'].post update: x-apievangelist-phrasing: intent: Validate changes to an existing policy (deprecated) effect: read questions: - Can I check an edit to an existing policy is valid before saving it? - Does the legacy validator for policy updates still work? instructions: - text: 'Validate an update to policy {policy} on {levelType} {level}: name {name}, description {description}, statement {statement}.' slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id name: requestBody.name description: requestBody.description statement: requestBody.statementQuery - text: Dry-run my edit of existing policy {policy} at {levelType} {level} with statement {statement}, name {name}, description {description}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id statement: requestBody.statementQuery name: requestBody.name description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/resolution/{level-type}/{level-id}/effectivepermissions'].get update: x-apievangelist-phrasing: intent: Get effective permissions for a user or group effect: read questions: - What can a given user actually do once all their policies are combined? - Can I resolve a group's effective permissions for specific services? instructions: - text: Resolve effective permissions for {entityType} {entity} on {levelType} {level}. slots: entityType: query.entityType entity: query.entityId levelType: path.level-type level: path.level-id - text: Show what {entityType} {entity} is allowed to do in {services} at {levelType} {level}. slots: entityType: query.entityType entity: query.entityId services: query.services levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies/aggregate'].get update: x-apievangelist-phrasing: intent: List policies for a level including inherited ones effect: read questions: - Which policies apply to an environment, including ones inherited from the account? - Can I see an aggregated policy overview across parent levels? instructions: - text: List all policies at {levelType} {level}, including inherited ones. slots: levelType: path.level-type level: path.level-id - text: Show the aggregated policy overview for {levelType} {level}. slots: levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies'].get update: x-apievangelist-phrasing: intent: List policies defined natively on a level effect: read questions: - Which policies were created directly on this level, not inherited? - Can I filter a level's own policies by name or category? instructions: - text: List the native policies on {levelType} {level}. slots: levelType: path.level-type level: path.level-id - text: Find policies named {name} defined on {levelType} {level}. slots: name: query.name levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies'].post update: x-apievangelist-phrasing: intent: Create an IAM policy effect: write questions: - How do I write a new IAM policy with my own statement? - Can policies be created at the environment level? instructions: - text: Create policy {name} on {levelType} {level} with statement {statement} and description {description}. slots: name: requestBody.name levelType: path.level-type level: path.level-id statement: requestBody.statementQuery description: requestBody.description - text: Add a new {levelType} policy at {level} called {name}, described {description}, allowing {statement}. slots: levelType: path.level-type level: path.level-id name: requestBody.name description: requestBody.description statement: requestBody.statementQuery method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies/{policy-uuid}'].get update: x-apievangelist-phrasing: intent: Get one policy's statement and details effect: read questions: - What statement does a specific policy contain? - Can I read a single policy by its UUID? instructions: - text: Get policy {policy} on {levelType} {level}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id - text: Show me the statement of policy {policy} at {levelType} {level}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies/{policy-uuid}'].put update: x-apievangelist-phrasing: intent: Update or create a policy by UUID effect: write questions: - How do I change the statement of an existing policy? - Does updating a policy UUID that doesn't exist create it? instructions: - text: Update policy {policy} on {levelType} {level} to statement {statement}, name {name}, description {description}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id statement: requestBody.statementQuery name: requestBody.name description: requestBody.description - text: Save policy {policy} at {levelType} {level} as {name} ({description}) with statement {statement}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id name: requestBody.name description: requestBody.description statement: requestBody.statementQuery method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/policies/{policy-uuid}'].delete update: x-apievangelist-phrasing: intent: Delete a policy effect: destructive questions: - Can I delete a policy that is still bound to groups? - What does the force flag do when removing a policy? instructions: - text: Delete policy {policy} from {levelType} {level} with force {force}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id force: query.force - text: Remove the policy {policy} at {levelType} {level}, force={force}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id force: query.force method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/groups/{group-uuid}'].get update: x-apievangelist-phrasing: intent: List the policies bound to a user group effect: read questions: - Which policies does a particular group have attached? - Can I get full policy details, not just IDs, for a group's bindings? instructions: - text: List the policies bound to group {group} at {levelType} {level}. slots: group: path.group-uuid levelType: path.level-type level: path.level-id - text: Show group {group}'s attached policies on {levelType} {level} with details {details}. slots: group: path.group-uuid levelType: path.level-type level: path.level-id details: query.details method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/groups/{group-uuid}'].put update: x-apievangelist-phrasing: intent: Replace all policies bound to a group effect: write questions: - How do I set exactly which policies a group has, dropping the rest? - Does rebinding a group's policies overwrite its existing ones? instructions: - text: Bind group {group} at {levelType} {level} to exactly policies {policies}. slots: group: path.group-uuid levelType: path.level-type level: path.level-id policies: requestBody.policyUuids - text: Replace group {group}'s policy set on {levelType} {level} with {policies}. slots: group: path.group-uuid levelType: path.level-type level: path.level-id policies: requestBody.policyUuids method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings'].get update: x-apievangelist-phrasing: intent: List every policy binding on a level effect: read questions: - Which groups use which policies across a whole level? - Can I dump all policy-to-group bindings for an account? instructions: - text: List all policy bindings on {levelType} {level}. slots: levelType: path.level-type level: path.level-id - text: Show the full binding map of policies to groups at {levelType} {level}. slots: levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings'].delete update: x-apievangelist-phrasing: intent: Delete every policy binding on a level effect: destructive questions: - Is there a way to wipe all policy bindings from an environment at once? - What happens if I clear every binding on a level? instructions: - text: Delete all policy bindings on {levelType} {level}. slots: levelType: path.level-type level: path.level-id - text: Clear every group-policy binding at {levelType} {level}. slots: levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/{policy-uuid}'].get update: x-apievangelist-phrasing: intent: List the groups bound to one policy effect: read questions: - Which groups are using a specific policy on this level? - Who is affected if I change a given policy? instructions: - text: List the groups bound to policy {policy} at {levelType} {level}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id - text: Show bindings of policy {policy} on {levelType} {level}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/{policy-uuid}'].post update: x-apievangelist-phrasing: intent: Bind a policy to additional groups effect: write questions: - Can I attach one policy to several more groups without disturbing current bindings? - How do I bind a policy to groups with a boundary applied? instructions: - text: Bind policy {policy} at {levelType} {level} to groups {groups}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id groups: requestBody.groups - text: Attach policy {policy} on {levelType} {level} to groups {groups} limited by boundaries {boundaries}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id groups: requestBody.groups boundaries: requestBody.boundaries method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/{policy-uuid}'].delete update: x-apievangelist-phrasing: intent: Unbind a policy from all its groups effect: destructive questions: - How do I detach a policy from every group that uses it? - What does forceMultiple mean when unbinding a policy? instructions: - text: Remove all bindings of policy {policy} at {levelType} {level}, forceMultiple {force}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id force: query.forceMultiple - text: Detach policy {policy} from every group on {levelType} {level} with forceMultiple={force}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id force: query.forceMultiple method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/descendants/{policy-uuid}'].get update: x-apievangelist-phrasing: intent: List a policy's bindings in child levels effect: read questions: - Where is an account policy bound in the environments beneath it? - Can I see a policy's bindings across descendant levels? instructions: - text: List bindings of policy {policy} in levels below {levelType} {level}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id - text: Show descendant-level bindings for policy {policy} under {levelType} {level}, page {page}. slots: policy: path.policy-uuid levelType: path.level-type level: path.level-id page: query.page method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/{policy-uuid}/{group-uuid}'].get update: x-apievangelist-phrasing: intent: Get the binding between one policy and one group effect: read questions: - Is a specific policy bound to a specific group, and with what parameters? - Which boundaries apply to one group's binding of a policy? instructions: - text: Get the binding of policy {policy} to group {group} at {levelType} {level}. slots: policy: path.policy-uuid group: path.group-uuid levelType: path.level-type level: path.level-id - text: Check whether group {group} is bound to policy {policy} on {levelType} {level}. slots: group: path.group-uuid policy: path.policy-uuid levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/{policy-uuid}/{group-uuid}'].put update: x-apievangelist-phrasing: intent: Set one group's binding to a policy effect: write questions: - How do I change the parameters on one group's policy binding? - Can I create or overwrite a single policy-group binding with boundaries? instructions: - text: Set the binding of policy {policy} to group {group} at {levelType} {level} with parameters {parameters}. slots: policy: path.policy-uuid group: path.group-uuid levelType: path.level-type level: path.level-id parameters: requestBody.parameters - text: Overwrite group {group}'s binding to policy {policy} on {levelType} {level} using boundaries {boundaries}. slots: group: path.group-uuid policy: path.policy-uuid levelType: path.level-type level: path.level-id boundaries: requestBody.boundaries method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/{policy-uuid}/{group-uuid}'].post update: x-apievangelist-phrasing: intent: Append a binding of a policy for one group effect: write questions: - Can I add another parameterised binding of a policy for a group, keeping the old one? - What's the way to stack an extra boundary-limited binding on one group? instructions: - text: Append a binding of policy {policy} for group {group} at {levelType} {level} with parameters {parameters}. slots: policy: path.policy-uuid group: path.group-uuid levelType: path.level-type level: path.level-id parameters: requestBody.parameters - text: Add an extra binding for group {group} to policy {policy} on {levelType} {level}, keeping existing ones. slots: group: path.group-uuid policy: path.policy-uuid levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/bindings/{policy-uuid}/{group-uuid}'].delete update: x-apievangelist-phrasing: intent: Unbind a policy from one group effect: destructive questions: - How do I detach a single policy from just one group? - Can I remove one group's policy binding while other groups keep it? instructions: - text: Unbind policy {policy} from group {group} at {levelType} {level}, forceMultiple {force}. slots: policy: path.policy-uuid group: path.group-uuid levelType: path.level-type level: path.level-id force: query.forceMultiple - text: Remove group {group}'s binding to policy {policy} on {levelType} {level} with forceMultiple={force}. slots: group: path.group-uuid policy: path.policy-uuid levelType: path.level-type level: path.level-id force: query.forceMultiple method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/account/{account-id}/boundaries'].get update: x-apievangelist-phrasing: intent: List policy boundaries in an account effect: read questions: - What policy boundaries have been defined for my account? - Can I page through the list of boundaries? instructions: - text: List the policy boundaries on account {account}. slots: account: path.account-id - text: Show page {page} of boundaries for account {account}. slots: page: query.page account: path.account-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/account/{account-id}/boundaries'].post update: x-apievangelist-phrasing: intent: Create a policy boundary effect: write questions: - How do I restrict a policy's reach to certain resources with a boundary? - What goes into a boundary query when creating one? instructions: - text: Create boundary {name} on account {account} with query {query} and metadata {metadata}. slots: name: requestBody.name account: path.account-id query: requestBody.boundaryQuery metadata: requestBody.metadata - text: Add a new policy boundary called {name} to {account} limiting to {query}, metadata {metadata}. slots: name: requestBody.name account: path.account-id query: requestBody.boundaryQuery metadata: requestBody.metadata method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/account/{account-id}/boundaries/{policy-boundary-uuid}'].get update: x-apievangelist-phrasing: intent: Get one policy boundary effect: read questions: - What does a particular boundary restrict? - Can I read a boundary's query by its UUID? instructions: - text: Get boundary {boundary} on account {account}. slots: boundary: path.policy-boundary-uuid account: path.account-id - text: Show the query of policy boundary {boundary} in {account}. slots: boundary: path.policy-boundary-uuid account: path.account-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/account/{account-id}/boundaries/{policy-boundary-uuid}'].put update: x-apievangelist-phrasing: intent: Update or create a policy boundary by UUID effect: write questions: - How do I change the query of an existing boundary? - Will updating a boundary UUID that doesn't exist create it? instructions: - text: Update boundary {boundary} on {account} to name {name}, query {query}, metadata {metadata}. slots: boundary: path.policy-boundary-uuid account: path.account-id name: requestBody.name query: requestBody.boundaryQuery metadata: requestBody.metadata - text: Save boundary {boundary} in account {account} as {name} restricting to {query} with metadata {metadata}. slots: boundary: path.policy-boundary-uuid account: path.account-id name: requestBody.name query: requestBody.boundaryQuery metadata: requestBody.metadata method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/account/{account-id}/boundaries/{policy-boundary-uuid}'].delete update: x-apievangelist-phrasing: intent: Delete a policy boundary effect: destructive questions: - Can I delete a boundary I no longer need? - How do I remove a policy boundary from my account? instructions: - text: Delete boundary {boundary} from account {account}. slots: boundary: path.policy-boundary-uuid account: path.account-id - text: Remove policy boundary {boundary} on {account}. slots: boundary: path.policy-boundary-uuid account: path.account-id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/repo/{level-type}/{level-id}/limits'].get update: x-apievangelist-phrasing: intent: Show the IAM limits for a level effect: read questions: - How many policies or bindings can an environment hold? - What IAM limits apply at a specific level? instructions: - text: Show the limits defined for {levelType} {level}. slots: levelType: path.level-type level: path.level-id - text: Check the policy and binding caps on {levelType} {level}. slots: levelType: path.level-type level: path.level-id method: generated generated: '2026-09-26'