# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview Cloud Accounts API version: 1.0.0 extends: openapi/palo-alto-networks-cloud-accounts-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 35 - target: $.paths['/cloud'].get update: x-apievangelist-phrasing: intent: List all onboarded cloud accounts effect: read questions: - Which cloud accounts are onboarded to Prisma Cloud right now? - Can I list my cloud accounts without the account group details attached? instructions: - text: List every cloud account onboarded to Prisma Cloud. - text: 'Show all onboarded cloud accounts, excluding account group details: {exclude}.' slots: exclude: query.excludeAccountGroupDetails method: generated generated: '2026-09-26' - target: $.paths['/cloud/name'].get update: x-apievangelist-phrasing: intent: Get cloud account IDs and names effect: read questions: - What are the IDs and names of my active cloud accounts? - Can I get just account names for one cloud type using a simple GET lookup? instructions: - text: Get the IDs and names of only active cloud accounts. - text: Look up account names and IDs for cloud type {cloudType} via the GET name list. slots: cloudType: query.cloudType - text: Get account names for account groups {accountGroupIds}. slots: accountGroupIds: query.accountGroupIds method: generated generated: '2026-09-26' - target: $.paths['/cloud/name'].post update: x-apievangelist-phrasing: intent: Look up cloud account names with a filter body effect: read questions: - Can I filter cloud account names by a time range and a filter key in a POST body? - Is there a way to get cloud account names grouped by a field for specific account IDs? instructions: - text: Post a cloud account name lookup for time range {timeRange}. slots: timeRange: requestBody.timeRange - text: Fetch account names for account IDs {accountIds} within {timeRange}, grouped by {groupBy}. slots: accountIds: requestBody.accountIds timeRange: requestBody.timeRange groupBy: requestBody.groupBy method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/{id}/project'].get update: x-apievangelist-phrasing: intent: List member accounts under a cloud organization effect: read questions: - Which child accounts or projects sit under my onboarded cloud organization? - Can I see all the member accounts onboarded as children of one org account? instructions: - text: List the child accounts of {cloud_type} organization {id}. slots: cloud_type: path.cloud_type id: path.id - text: Show the projects onboarded under org account {id} on {cloud_type} without group details. slots: id: path.id cloud_type: path.cloud_type method: generated generated: '2026-09-26' - target: $.paths['/cloud/type'].get update: x-apievangelist-phrasing: intent: List supported cloud types effect: read questions: - What cloud types does Prisma Cloud support? - Which cloud types do I personally have access to? instructions: - text: List all cloud types. - text: Show only the cloud types I can access. method: generated generated: '2026-09-26' - target: $.paths['/cloud/{id}/owners'].get update: x-apievangelist-phrasing: intent: List owner emails for a cloud account effect: read questions: - Who owns this cloud account? - Where can I find the owner email addresses for an onboarded account? instructions: - text: Get the owner email addresses for cloud account {id}. slots: id: path.id - text: Tell me who owns account {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}'].post update: x-apievangelist-phrasing: intent: Onboard a cloud account by cloud type effect: write questions: - How do I onboard a new Azure, GCP or Alibaba account into Prisma Cloud? - Can I skip the account status checks to speed up onboarding a cloud account? instructions: - text: Onboard a new {cloud_type} cloud account. slots: cloud_type: path.cloud_type - text: Add a {cloud_type} account and skip status checks. slots: cloud_type: path.cloud_type method: generated generated: '2026-09-26' - target: $.paths['/cloud/oci/terraform'].post update: x-apievangelist-phrasing: intent: Generate an OCI onboarding Terraform script effect: write questions: - How do I get a Terraform template to onboard my Oracle Cloud tenancy? - Can the OCI onboarding script also generate keys, and how long do they last? instructions: - text: Generate the OCI Terraform zip for tenancy {accountId} with user {userName}, group {groupName} and policy {policyName}. slots: accountId: requestBody.accountId userName: requestBody.userName groupName: requestBody.groupName policyName: requestBody.policyName - text: Create an OCI onboarding script with generated keys for tenancy {accountId}. slots: accountId: requestBody.accountId method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/{id}'].get update: x-apievangelist-phrasing: intent: Get details of one cloud account effect: read questions: - What top-level details does Prisma Cloud hold for a specific cloud account? - Can I see which account groups a given cloud account belongs to? instructions: - text: Get info for {cloud_type} account {id}. slots: cloud_type: path.cloud_type id: path.id - text: Show {cloud_type} account {id} including its account group info. slots: cloud_type: path.cloud_type id: path.id method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/{id}'].put update: x-apievangelist-phrasing: intent: Update a cloud account by cloud type effect: write questions: - How do I change the onboarding settings of an existing non-AWS cloud account? - Can I update a cloud account's configuration without waiting for status checks? instructions: - text: Update the configuration of {cloud_type} account {id}. slots: cloud_type: path.cloud_type id: path.id - text: Save changes to {cloud_type} account {id} and skip status checks. slots: cloud_type: path.cloud_type id: path.id method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/{id}'].delete update: x-apievangelist-phrasing: intent: Remove an onboarded cloud account effect: destructive questions: - How do I offboard a cloud account from Prisma Cloud? - What happens if I delete a cloud account that's been onboarded? instructions: - text: Delete {cloud_type} account {id}. slots: cloud_type: path.cloud_type id: path.id - text: Offboard cloud account {id} of type {cloud_type}. slots: id: path.id cloud_type: path.cloud_type method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/{id}'].patch update: x-apievangelist-phrasing: intent: Update a cloud account’s settings effect: write questions: - Can I change the account groups on an onboarded cloud account or switch it off? - Is it possible to update child account status along with the parent account? instructions: - text: Move {cloud_type} account {id} into account groups {groupIds}. slots: cloud_type: path.cloud_type id: path.id groupIds: requestBody.groupIds - text: Set enabled to {enabled} on {cloud_type} account {id} and apply it to child accounts with {updateChildrenStatus}. slots: enabled: requestBody.enabled cloud_type: path.cloud_type id: path.id updateChildrenStatus: requestBody.updateChildrenStatus method: generated generated: '2026-10-01' - target: $.paths['/account/{accountId}/config/status'].get update: x-apievangelist-phrasing: intent: Show services with warnings for an account effect: read questions: - Which Prisma Cloud services are showing warnings or errors for my account? - Why is my cloud account in an error state? instructions: - text: List the services with warning or error status for account {accountId}. slots: accountId: path.accountId - text: Show the config status details of cloud account {accountId}. slots: accountId: path.accountId method: generated generated: '2026-09-26' - target: $.paths['/cloud/status/{cloud_type}'].post update: x-apievangelist-phrasing: intent: Dry-run onboarding checks for a cloud type effect: read questions: - Can I validate my onboarding parameters before actually adding an account? - How do I run a trial onboarding for an Azure or GCP account? instructions: - text: Run an onboarding trial for a {cloud_type} account. slots: cloud_type: path.cloud_type - text: Validate my {cloud_type} account parameters before onboarding. slots: cloud_type: path.cloud_type method: generated generated: '2026-09-26' - target: $.paths['/cloud/{id}/status/{enabled}'].patch update: x-apievangelist-phrasing: intent: Enable or disable a cloud account effect: write questions: - What's the quickest way to turn monitoring off for one cloud account? - Can I re-enable an account and its children just by setting a status flag? instructions: - text: Set the status of cloud account {id} to {enabled}. slots: id: path.id enabled: path.enabled - text: Disable account {id} by setting enabled to {enabled} and apply to children. slots: id: path.id enabled: path.enabled method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/accounts/{account_id}/hierarchy'].get update: x-apievangelist-phrasing: intent: Get the saved GCP resource hierarchy effect: read questions: - Where can I see the GCP folder and project hierarchy I saved earlier? - What resource hierarchy was stored for my GCP org account? instructions: - text: Get the saved resource hierarchy for GCP account {account_id} of type {cloud_type}. slots: account_id: path.account_id cloud_type: path.cloud_type - text: Show the previously saved hierarchy of {cloud_type} account {account_id}. slots: cloud_type: path.cloud_type account_id: path.account_id method: generated generated: '2026-09-26' - target: $.paths['/cloud/gcp/parent/{parent_id}/children'].post update: x-apievangelist-phrasing: intent: List GCP folders and projects under a parent effect: read questions: - How can I see both folders and projects beneath a GCP organization? - Can I page through GCP projects and folders under a parent separately? instructions: - text: List the folders and projects under GCP parent {parent_id} of type {parentType}. slots: parent_id: path.parent_id parentType: query.parentType - text: Get all children of GCP {parentType} {parent_id} using my service account key {credentials}. slots: parentType: query.parentType parent_id: path.parent_id credentials: requestBody.credentials method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/parent/{parent_id}/folders'].post update: x-apievangelist-phrasing: intent: List GCP child folders of a parent effect: read questions: - Which GCP folders sit directly under my organization or folder? - Can I list only the folders, not projects, under a GCP parent? instructions: - text: List only the child folders of GCP {parentType} {parent_id} for {cloud_type}. slots: parentType: query.parentType parent_id: path.parent_id cloud_type: path.cloud_type - text: Page through GCP folders under {parent_id} with page size {pageSize}; parent type {parentType}, cloud {cloud_type}. slots: parent_id: path.parent_id pageSize: query.pageSize parentType: query.parentType cloud_type: path.cloud_type method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/parent/{parent_id}/projects'].post update: x-apievangelist-phrasing: intent: List GCP child projects of a parent effect: read questions: - What GCP projects live under a given folder? - Can I list only the projects, skipping folders, beneath a GCP org? instructions: - text: List the child projects of GCP {parentType} {parent_id} for {cloud_type}. slots: parentType: query.parentType parent_id: path.parent_id cloud_type: path.cloud_type - text: Page GCP projects under {parent_id} with page size {pageSize}; parent type {parentType}, cloud {cloud_type}. slots: parent_id: path.parent_id pageSize: query.pageSize parentType: query.parentType cloud_type: path.cloud_type method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloud_type}/accounts/{account_id}/ancestors'].post update: x-apievangelist-phrasing: intent: Find ancestors of GCP projects and folders effect: read questions: - Which parent folders and org does a given GCP project roll up to? - Can I map several GCP projects to their ancestor chain at once? instructions: - text: Get the GCP ancestors of resources {resourceIds} in {cloud_type} account {account_id}. slots: resourceIds: requestBody.resourceIds cloud_type: path.cloud_type account_id: path.account_id - text: Show the ancestor chain for GCP projects in account {account_id} of type {cloud_type}. slots: account_id: path.account_id cloud_type: path.cloud_type method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/azureAccounts/{parent_id}/children'].post update: x-apievangelist-phrasing: intent: List Azure subscriptions and groups under a parent effect: read questions: - What subscriptions and management groups are under my Azure tenant? - Can I browse the children of an Azure management group? instructions: - text: List Azure subscriptions and management groups under parent {parent_id}. slots: parent_id: path.parent_id - text: Show the children of Azure management group {parent_id}. slots: parent_id: path.parent_id method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/azureAccounts/{account_id}/ancestors'].post update: x-apievangelist-phrasing: intent: Find ancestors of Azure subscriptions effect: read questions: - Which management groups does an Azure subscription roll up to? - Can I get the ancestor path for several Azure subscriptions at once? instructions: - text: Get the Azure ancestors of {resourceIds} in tenant account {account_id}. slots: resourceIds: requestBody.resourceIds account_id: path.account_id - text: Show the management group ancestry for Azure tenant {account_id}. slots: account_id: path.account_id method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/config/awsorg/status'].post update: x-apievangelist-phrasing: intent: Check AWS org data security prerequisites effect: read questions: - Does my AWS Organization meet the prerequisites for data security scanning? - What does Prisma Cloud check before I can set up data security for an AWS org? instructions: - text: Check data security preconditions for AWS org {accountId} with role {roleArn}, external ID {externalId} and SNS topic {snsTopicArn}. slots: accountId: requestBody.accountId roleArn: requestBody.roleArn externalId: requestBody.externalId snsTopicArn: requestBody.snsTopicArn - text: Verify AWS org {accountId} is ready for a data security config. slots: accountId: requestBody.accountId method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/config/v2'].put update: x-apievangelist-phrasing: intent: Update data security config for an AWS org effect: write questions: - How do I change the scan option on an existing AWS org data security config? - Can I rotate the member role name used by an AWS org data security scan? instructions: - text: Update the AWS org data security config for {accountId} to scan option {scanOption}. slots: accountId: requestBody.accountId scanOption: requestBody.scanOption - text: Change the existing data security scan of AWS org {accountId} to use member role {memberRoleName}. slots: accountId: requestBody.accountId memberRoleName: requestBody.memberRoleName method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/config/v2'].post update: x-apievangelist-phrasing: intent: Create a data security config for an AWS org effect: write questions: - How do I turn on data security scanning for my whole AWS Organization? - What do I need, like role ARNs and an SNS topic, to create an AWS org data security config? instructions: - text: Create a data security config for AWS org {accountId} with master role {masterRoleArn} and SNS topic {snsTopicArn}. slots: accountId: requestBody.accountId masterRoleArn: requestBody.masterRoleArn snsTopicArn: requestBody.snsTopicArn - text: Start data security scanning on AWS org {accountId} with scan option {scanOption}. slots: accountId: requestBody.accountId scanOption: requestBody.scanOption method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/config/v2/{accountId}'].get update: x-apievangelist-phrasing: intent: Get the data security config of an AWS org effect: read questions: - What data security scan settings are configured for my AWS org? - Is data security already configured for this AWS Organization? instructions: - text: Get the data security config for AWS org {accountId}. slots: accountId: path.accountId - text: Show the scan settings on AWS org account {accountId}. slots: accountId: path.accountId method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{parent_id}/children'].post update: x-apievangelist-phrasing: intent: List AWS OU children (legacy endpoint) effect: read questions: - Is there still a legacy endpoint to list accounts and OUs under an AWS organizational unit? - Can I page AWS child accounts under an OU using the older cloud accounts manager path? instructions: - text: Using the legacy endpoint, list the accounts and OUs under AWS OU {parent_id}. slots: parent_id: path.parent_id - text: 'Legacy lookup: fetch {accountFetchCount} child accounts of AWS OU {parent_id}.' slots: accountFetchCount: query.accountFetchCount parent_id: path.parent_id method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{account_id}/ancestors'].post update: x-apievangelist-phrasing: intent: Find AWS account ancestors (legacy endpoint) effect: read questions: - Does the older cloud accounts manager API still return ancestors for AWS member accounts? - Where's the legacy call that maps AWS OUs to their parents? instructions: - text: Using the legacy endpoint, get ancestors of members in AWS account {account_id}. slots: account_id: path.account_id - text: 'Legacy lookup: show the OU ancestry for AWS org account {account_id}.' slots: account_id: path.account_id method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_account'].post update: x-apievangelist-phrasing: intent: Onboard an AWS account effect: write questions: - How do I onboard an AWS account or organization using a role ARN? - Can I choose which features to enable when adding an AWS account? instructions: - text: Onboard AWS account {accountId} named {name} with role {roleArn} as type {accountType}. slots: accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn accountType: requestBody.accountType - text: Add AWS organization {accountId} as {name} using role {roleArn} into account group {defaultAccountGroupId}; type {accountType}. slots: accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn defaultAccountGroupId: requestBody.defaultAccountGroupId accountType: requestBody.accountType method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_account/{id}'].put update: x-apievangelist-phrasing: intent: Update an onboarded AWS account effect: write questions: - How do I change the role ARN or features of an AWS account already onboarded? - Can I rename an existing AWS cloud account? instructions: - text: Update AWS cloud account {id} with new role {roleArn}; AWS ID {accountId}, name {name}, type {accountType}. slots: id: path.id roleArn: requestBody.roleArn accountId: requestBody.accountId name: requestBody.name accountType: requestBody.accountType - text: Rename AWS cloud account {id} to {name}. slots: id: path.id name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/cloud_account/status/aws'].post update: x-apievangelist-phrasing: intent: Check an AWS account onboarding status effect: read questions: - Will my AWS role ARN and settings pass Prisma Cloud's account checks? - What status messages come back for an AWS account before or after onboarding? instructions: - text: Check the AWS status messages for account {accountId} with role {roleArn}; name {name}, type {accountType}. slots: accountId: requestBody.accountId roleArn: requestBody.roleArn name: requestBody.name accountType: requestBody.accountType - text: Validate AWS account {accountId} permissions. slots: accountId: requestBody.accountId method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_account/{parent_id}/children'].post update: x-apievangelist-phrasing: intent: List AWS accounts and OUs under an OU effect: read questions: - Which AWS accounts and organizational units are under a given OU? - Can I browse my AWS org tree one OU at a time? instructions: - text: List the AWS accounts and OUs under OU {parent_id} for org {accountId} with role {roleArn}, type {accountType}. slots: parent_id: path.parent_id accountId: requestBody.accountId roleArn: requestBody.roleArn accountType: requestBody.accountType - text: Show the child OUs of AWS OU {parent_id}. slots: parent_id: path.parent_id method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_account/{account_id}/ancestors'].post update: x-apievangelist-phrasing: intent: Find ancestors of AWS accounts and OUs effect: read questions: - Which OUs does an AWS member account sit under? - Can I get the parent chain for several AWS accounts in one request? instructions: - text: Get the ancestors of AWS resources {resourceIds} in org account {account_id}. slots: resourceIds: requestBody.resourceIds account_id: path.account_id - text: Map AWS accounts {resourceIds} to their OU ancestry using role {roleArn} for {accountId}, type {accountType}. slots: resourceIds: requestBody.resourceIds roleArn: requestBody.roleArn accountId: requestBody.accountId accountType: requestBody.accountType method: generated generated: '2026-09-26' - target: $.paths['/cloud/{cloudType}'].post update: x-apievangelist-phrasing: intent: Onboard a named cloud account with account groups effect: write questions: - What do I need to supply, like the provider account ID and a display name, to start monitoring an AWS or OCI account? - Can I attach account groups to a cloud account at the moment I onboard it? - Is it possible to onboard a cloud account with monitoring switched off at first? instructions: - text: Onboard {cloudType} account {accountId} under the display name {name}. slots: cloudType: path.cloudType accountId: requestBody.accountId name: requestBody.name - text: Start monitoring {cloudType} account {accountId} as {name} and put it in account groups {groupIds}. slots: cloudType: path.cloudType accountId: requestBody.accountId name: requestBody.name groupIds: requestBody.groupIds method: generated generated: '2026-10-01' - target: $.paths['/cloud/{cloudType}/{id}'].delete update: x-apievangelist-phrasing: intent: Stop monitoring a cloud account, keeping its alerts effect: destructive questions: - How can I stop Prisma Cloud monitoring an account but keep its old alerts for historical analysis? - Are alerts and data kept after a cloud account is removed from monitoring? instructions: - text: Remove {cloudType} account {id} from monitoring but keep its alert history. slots: cloudType: path.cloudType id: path.id - text: Stop monitoring cloud account {id} ({cloudType}) and retain its historical data. slots: id: path.id cloudType: path.cloudType method: generated generated: '2026-10-01'