# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Onetrust Users V2 API version: 1.0.0 extends: openapi/onetrust-users-v2-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/api/access/v2/users'].get update: x-apievangelist-phrasing: intent: List all users in the account effect: read questions: - Who are all the users in my OneTrust account? - Can I page through the account's user list and sort it? instructions: - text: List every user in my account, sorted by {sort}. slots: sort: query.sort - text: Show page {page} of the account users with {size} per page. slots: page: query.page size: query.size method: generated generated: '2026-09-26' - target: $.paths['/api/access/v2/users'].post update: x-apievangelist-phrasing: intent: Create a new user in the account effect: write questions: - How do I add a new person as a user in my privacy account? - Can I create a user without sending them a notification email? instructions: - text: Add a user named {firstName} {lastName} with email {email}. slots: firstName: requestBody.firstName lastName: requestBody.lastName email: requestBody.email - text: Create user {email} ({firstName} {lastName}) whose access expires at {expirationDateTime}. slots: email: requestBody.email firstName: requestBody.firstName lastName: requestBody.lastName expirationDateTime: requestBody.expirationDateTime method: generated generated: '2026-09-26' - target: $.paths['/api/access/v2/users/{userId}'].get update: x-apievangelist-phrasing: intent: Get one user's account details effect: read questions: - What details are stored for a single user in my account? - Can I look up one account user by their user ID? instructions: - text: Show the account details for user {userId}. slots: userId: path.userId - text: Look up user {userId} and tell me their name, email and access levels. slots: userId: path.userId method: generated generated: '2026-09-26' - target: $.paths['/api/access/v2/users/{userId}'].put update: x-apievangelist-phrasing: intent: Update a user's name and access details effect: write questions: - How do I change a user's name or expiration date in the account? - Can I mark an existing user as internal or external? instructions: - text: Rename user {userId} to {firstName} {lastName}. slots: userId: path.userId firstName: requestBody.firstName lastName: requestBody.lastName - text: Set the access expiration of user {userId} ({firstName} {lastName}) to {expirationDateTime}. slots: userId: path.userId firstName: requestBody.firstName lastName: requestBody.lastName expirationDateTime: requestBody.expirationDateTime method: generated generated: '2026-09-26' - target: $.paths['/api/access/v2/users/{userId}/access-levels'].get update: x-apievangelist-phrasing: intent: List the roles assigned to a user effect: read questions: - Which roles does a particular user hold? - What access levels has this user been granted across organizations? instructions: - text: List the roles assigned to user {userId}. slots: userId: path.userId - text: Tell me which organizations and roles user {userId} has. slots: userId: path.userId method: generated generated: '2026-09-26' - target: $.paths['/api/access/v2/users/{userId}/access-levels'].post update: x-apievangelist-phrasing: intent: Grant a role to a user in an organization effect: write questions: - How do I give a user an additional role? - Can I grant someone a role scoped to a specific organization? instructions: - text: Grant role {roleId} in organization {organizationId} to user {userId}. slots: roleId: requestBody.roleId organizationId: requestBody.organizationId userId: path.userId - text: Give user {userId} the {roleId} role for organization {organizationId}. slots: userId: path.userId roleId: requestBody.roleId organizationId: requestBody.organizationId method: generated generated: '2026-09-26' - target: $.paths['/api/access/v2/users/{userId}/access-levels'].delete update: x-apievangelist-phrasing: intent: Remove a role from a user effect: destructive questions: - How do I take a role away from a user? - Can I revoke a user's role in just one organization? instructions: - text: Remove role {roleId} in organization {organizationId} from user {userId}. slots: roleId: requestBody.roleId organizationId: requestBody.organizationId userId: path.userId - text: Revoke user {userId}'s {roleId} role in organization {organizationId}. slots: userId: path.userId roleId: requestBody.roleId organizationId: requestBody.organizationId method: generated generated: '2026-09-26' - target: $.paths['/api/access/v2/users/{userId}/default-organization'].patch update: x-apievangelist-phrasing: intent: Change a user's default organization effect: write questions: - How do I change which organization a user lands in by default? - Does the user need a role in an organization before it can be their default? instructions: - text: Make organization {organizationId} the default for user {userId}. slots: organizationId: query.organizationId userId: path.userId - text: Switch user {userId}'s default organization to {organizationId}. slots: userId: path.userId organizationId: query.organizationId method: generated generated: '2026-09-26' - target: $.paths['/api/scim/v2/Users'].get update: x-apievangelist-phrasing: intent: List users through the SCIM provisioning endpoint effect: read questions: - How does my identity provider list users over SCIM? - Can a SCIM sync page through users with a start index and count? instructions: - text: List SCIM-provisioned users starting at index {startIndex}, {count} at a time. slots: startIndex: query.startIndex count: query.count - text: Fetch the SCIM user list with created and last modified dates. method: generated generated: '2026-09-26' - target: $.paths['/api/scim/v2/Users'].post update: x-apievangelist-phrasing: intent: Provision a user from an identity provider via SCIM effect: write questions: - How do I provision a new user from my identity provider over SCIM? - Can a SCIM-created user be assigned roles and groups at creation? instructions: - text: Provision SCIM user {userName} with emails {emails}. slots: userName: requestBody.userName emails: requestBody.emails - text: Create a SCIM user {userName} with roles {roles} and title {title}. slots: userName: requestBody.userName roles: requestBody.roles title: requestBody.title method: generated generated: '2026-09-26' - target: $.paths['/api/scim/v2/Users/{id}'].get update: x-apievangelist-phrasing: intent: Get a SCIM user and their groups effect: read questions: - Which SCIM groups does a provisioned user belong to? - What does the SCIM record for one provisioned user look like? instructions: - text: Get the SCIM record for user {id}. slots: id: path.id - text: Show which SCIM groups provisioned user {id} belongs to. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/scim/v2/Users/{id}'].put update: x-apievangelist-phrasing: intent: Replace all attributes of a SCIM user effect: write questions: - How do I fully overwrite a provisioned user's attributes over SCIM? - Can a SCIM full replace change a user's userName and emails together? instructions: - text: Replace the full SCIM record of user {id} with userName {userName} and emails {emails}. slots: id: path.id userName: requestBody.userName emails: requestBody.emails - text: Overwrite SCIM user {id} so that active is {active} and title is {title}. slots: id: path.id active: requestBody.active title: requestBody.title method: generated generated: '2026-09-26' - target: $.paths['/api/scim/v2/Users/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a SCIM user (not currently available) effect: destructive questions: - Can I delete a provisioned user through the SCIM endpoint? - Is SCIM user deletion supported right now? instructions: - text: Delete SCIM user {id}. slots: id: path.id - text: Remove provisioned user {id} through the SCIM delete endpoint. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/scim/v2/Users/{id}'].patch update: x-apievangelist-phrasing: intent: Activate, deactivate or patch a SCIM user effect: write questions: - How do I deactivate a user from my identity provider over SCIM? - Can I partially update a SCIM user instead of replacing them? instructions: - text: Deactivate SCIM user {id}. slots: id: path.id - text: Apply the SCIM patch operations {Operations} to user {id}. slots: Operations: requestBody.Operations id: path.id method: generated generated: '2026-09-26'