# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Access Policies API version: 1.0.0 extends: openapi/palo-alto-networks-access-policies-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 9 - target: $.paths['/access-policies'].get update: x-apievangelist-phrasing: intent: List access policies for a tenant effect: read questions: - Which roles has each service account or user been granted across my tenant service groups? - Can I list the access policies for one principal or one TSG? instructions: - text: List access policies for principal {principal_id}. slots: principal_id: query.principal_id - text: Show access policies scoped to TSG {tsg_id}. slots: tsg_id: query.tsg_id method: generated generated: '2026-09-26' - target: $.paths['/access-policies'].post update: x-apievangelist-phrasing: intent: Grant a role to a principal in a TSG effect: write questions: - How do I give a service account a role within a tenant service group? - What do I need to bind a user to a role for API access? instructions: - text: Grant role {role_id} to {principal_type} {principal_id} in TSG {tsg_id}. slots: role_id: requestBody.role_id principal_type: requestBody.principal_type principal_id: requestBody.principal_id tsg_id: requestBody.tsg_id - text: Create an access policy binding {principal_type} {principal_id} to role {role_id} on tenant {tsg_id}. slots: principal_type: requestBody.principal_type principal_id: requestBody.principal_id role_id: requestBody.role_id tsg_id: requestBody.tsg_id method: generated generated: '2026-09-26' - target: $.paths['/access-policies/{id}'].get update: x-apievangelist-phrasing: intent: Get an access policy effect: read questions: - Which principal, role and TSG does one access policy bind? - What details are stored on a specific access policy? instructions: - text: Get access policy {id}. slots: id: path.id - text: Show the role binding in access policy {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/access-policies/{id}'].put update: x-apievangelist-phrasing: intent: Change the role on an access policy effect: write questions: - Can I switch a principal to a different role without recreating the access policy? - How do I update an existing role assignment? instructions: - text: Change access policy {id} to role {role_id} for {principal_type} {principal_id} in TSG {tsg_id}. slots: id: path.id role_id: requestBody.role_id principal_type: requestBody.principal_type principal_id: requestBody.principal_id tsg_id: requestBody.tsg_id - text: Update the role assignment on policy {id} to {role_id}, keeping principal {principal_id} ({principal_type}) and TSG {tsg_id}. slots: id: path.id role_id: requestBody.role_id principal_id: requestBody.principal_id principal_type: requestBody.principal_type tsg_id: requestBody.tsg_id method: generated generated: '2026-09-26' - target: $.paths['/access-policies/{id}'].delete update: x-apievangelist-phrasing: intent: Revoke an access policy effect: destructive questions: - Can I revoke a role binding from a service account? - Does deleting an access policy remove the principal's permissions? instructions: - text: Delete access policy {id}. slots: id: path.id - text: Revoke the role binding in access policy {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/access_policies'].get update: x-apievangelist-phrasing: intent: List IAM access policies effect: read questions: - Which access policies grant a particular role in my tenant? - What roles has a specific user or service account been assigned? instructions: - text: List all access policies using role {role}. slots: role: query.role - text: Show access policies assigned to {principal}. slots: principal: query.principal method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/access_policies'].post update: x-apievangelist-phrasing: intent: Assign an access policy to a user effect: write questions: - How do I give a user or service account a role on a tenant service group? - Does assigning an access policy to an unknown email create an SSO account? instructions: - text: Assign role {role} to {principal} on resource {resource}. slots: role: requestBody.role principal: requestBody.principal resource: requestBody.resource - text: Grant {principal} the {role} role for TSG {resource}. slots: principal: requestBody.principal role: requestBody.role resource: requestBody.resource method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/access_policies/{id}'].get update: x-apievangelist-phrasing: intent: Get an access policy effect: read questions: - What role and principal does a specific access policy contain? - Can I look up one IAM access policy by ID? instructions: - text: Get access policy {id} from the IAM v1 path. slots: id: path.id - text: Show who access policy {id} applies to. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/access_policies/{id}'].delete update: x-apievangelist-phrasing: intent: Revoke an access policy effect: destructive questions: - Can I remove a user's role by deleting their access policy? - What access is lost when an access policy is deleted? instructions: - text: Delete access policy {id} using the IAM v1 endpoint. slots: id: path.id - text: Revoke the role granted by access policy {id}. slots: id: path.id method: generated generated: '2026-10-01'