# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Cloud Accounts (AWS) API version: 1.0.0 extends: openapi/palo-alto-networks-cloud-accounts-aws-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 11 - target: $.paths['/cas/v1/aws_account'].post update: x-apievangelist-phrasing: intent: Onboard an AWS cloud account effect: write questions: - How do I onboard an AWS account into Prisma Cloud using an IAM role ARN? - Can I onboard a whole AWS organization rather than a single account? - Is there a way to skip status checks to speed up adding an AWS account? instructions: - text: Onboard AWS account {accountId} as {name} using role {roleArn}, account type {accountType}. slots: accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn accountType: requestBody.accountType - text: Add AWS {accountType} account {accountId} named {name} with role {roleArn} into account groups {groupIds}. slots: accountType: requestBody.accountType accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn groupIds: requestBody.groupIds method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_account/{account_id}/ancestors'].post update: x-apievangelist-phrasing: intent: List ancestors of AWS member accounts and OUs effect: read questions: - Which parent OUs sit above certain member accounts in my onboarded AWS organization? - Can I map a list of AWS account and OU IDs to their ancestor chain? instructions: - text: List the ancestors of resources {resourceIds} in AWS org account {account_id}, with AWS account {accountId}, role {roleArn}, type {accountType}. slots: resourceIds: requestBody.resourceIds account_id: path.account_id accountId: requestBody.accountId roleArn: requestBody.roleArn accountType: requestBody.accountType - text: Find parent OUs for {resourceIds} under cloud account {account_id} (AWS ID {accountId}, role {roleArn}, {accountType}). slots: resourceIds: requestBody.resourceIds account_id: path.account_id accountId: requestBody.accountId roleArn: requestBody.roleArn accountType: requestBody.accountType method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_account/{id}'].put update: x-apievangelist-phrasing: intent: Update an onboarded AWS cloud account effect: write questions: - How do I change the role ARN or features on an AWS account already in Prisma Cloud? - Can I move an onboarded AWS account into different account groups? instructions: - text: 'Update AWS cloud account {id}: AWS ID {accountId}, name {name}, role {roleArn}, type {accountType}.' slots: id: path.id accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn accountType: requestBody.accountType - text: Reassign onboarded AWS account {id} ({accountId}, {name}, role {roleArn}, {accountType}) to groups {groupIds}. slots: id: path.id accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn accountType: requestBody.accountType groupIds: requestBody.groupIds method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_account/{parent_id}/children'].post update: x-apievangelist-phrasing: intent: List child OUs and accounts under an AWS parent effect: read questions: - What accounts and OUs live directly under a given organizational unit in my AWS organization? - Can I page through child accounts and child OUs separately? instructions: - text: List children of AWS OU {parent_id} for account {accountId} with role {roleArn} and type {accountType}. slots: parent_id: path.parent_id accountId: requestBody.accountId roleArn: requestBody.roleArn accountType: requestBody.accountType - text: Get {accountFetchCount} child accounts under OU {parent_id} (AWS {accountId}, role {roleArn}, {accountType}). slots: accountFetchCount: query.accountFetchCount parent_id: path.parent_id accountId: requestBody.accountId roleArn: requestBody.roleArn accountType: requestBody.accountType method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/cloud_account/status/aws'].post update: x-apievangelist-phrasing: intent: Check the status of an AWS cloud account effect: read questions: - Why is my AWS account showing errors in Prisma Cloud — what do its status messages say? - Can I validate an AWS account's role and permissions before onboarding it? instructions: - text: Check status of AWS account {accountId} named {name} with role {roleArn}, type {accountType}. slots: accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn accountType: requestBody.accountType - text: Show status messages for AWS {accountType} account {accountId} ({name}) using role {roleArn}. slots: accountType: requestBody.accountType accountId: requestBody.accountId name: requestBody.name roleArn: requestBody.roleArn method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{account_id}/ancestors'].post update: x-apievangelist-phrasing: intent: List AWS ancestors via the legacy endpoint effect: read questions: - Is there an older cloud-accounts-manager endpoint for finding the ancestors of AWS member accounts? - Can I get ancestors for an AWS account with the legacy call that needs only the account ID? instructions: - text: Using the legacy cloud accounts manager, list ancestors for AWS account {account_id}. slots: account_id: path.account_id - text: Call the legacy AWS ancestors endpoint for cloud account {account_id}. slots: account_id: path.account_id method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{parent_id}/children'].post update: x-apievangelist-phrasing: intent: List AWS OU children via the legacy endpoint effect: read questions: - Is there a legacy call to list child accounts and OUs under an AWS parent without sending credentials in the body? - Can the older children endpoint page OUs with its own token? instructions: - text: Using the legacy cloud accounts manager, list children of OU {parent_id}. slots: parent_id: path.parent_id - text: Get {ouFetchCount} child OUs of {parent_id} from the legacy children endpoint. slots: ouFetchCount: query.ouFetchCount parent_id: path.parent_id method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_template/presigned_url'].post update: x-apievangelist-phrasing: intent: Generate an AWS CloudFormation quick-create link effect: write questions: - How do I get a CloudFormation quick-create link with a presigned template URL for onboarding AWS? - Can the generated stack link include permissions only for the features I select? instructions: - text: Generate a CloudFormation quick-create stack link for AWS account {accountId} of type {accountType}. slots: accountId: requestBody.accountId accountType: requestBody.accountType - text: Create a presigned CFT stack link for {accountType} account {accountId} with features {features}. slots: accountType: requestBody.accountType accountId: requestBody.accountId features: requestBody.features method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/aws_template'].post update: x-apievangelist-phrasing: intent: Download the AWS onboarding CFT template effect: write questions: - Where can I download the CloudFormation template file that creates the Prisma Cloud IAM role? - Does the downloadable CFT include the generated external ID? instructions: - text: Download the CFT template file for AWS account {accountId}, type {accountType}. slots: accountId: requestBody.accountId accountType: requestBody.accountType - text: Generate a {cftType} CFT template body for {accountType} account {accountId}. slots: cftType: requestBody.cftType accountType: requestBody.accountType accountId: requestBody.accountId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/account/awsorg/{id}'].get update: x-apievangelist-phrasing: intent: Get AWS Org master account details for PCDS effect: read questions: - What attributes define my AWS organization master account for data security flows? - Can I fetch the PCDS configuration of an AWS Org account? instructions: - text: Fetch the AWS Org master account details for {id}. slots: id: path.id - text: Show the PCDS config of AWS organization account {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/config/v3/account/awsorg/{id}/status'].get update: x-apievangelist-phrasing: intent: Check PCDS permissions on an AWS Org account effect: read questions: - Is my AWS Org account missing any permissions needed for data security scanning? - Can I run a permissions check on a PCDS AWS organization account? instructions: - text: Run the PCDS permissions check on AWS Org account {id}. slots: id: path.id - text: List missing permissions for AWS organization account {id}. slots: id: path.id method: generated generated: '2026-09-26'