# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Custom Roles API version: 1.0.0 extends: openapi/palo-alto-networks-custom-roles-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 5 - target: $.paths['/iam/v1/custom_roles'].get update: x-apievangelist-phrasing: intent: List custom roles effect: read questions: - Which custom IAM roles are available to my tenant service group? - What custom roles have been defined beyond the built-in ones? instructions: - text: List all custom roles for my tenant service group. - text: Show the custom IAM roles I can assign. method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/custom_roles'].post update: x-apievangelist-phrasing: intent: Create a custom role effect: write questions: - How do I create a custom role with only specific permissions? - Does a custom role name have to be unique in my TSG hierarchy? instructions: - text: Create custom role {name} described as {description}. slots: name: requestBody.name description: requestBody.description - text: Create custom role {name} ({description}) with permission sets {permission_sets}. slots: name: requestBody.name description: requestBody.description permission_sets: requestBody.permission_sets method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/custom_roles/{name}'].get update: x-apievangelist-phrasing: intent: Get a custom role effect: read questions: - What permissions does a particular custom role grant? - Can I look up a custom role by its name? instructions: - text: Show custom role {name}. slots: name: path.name - text: Get the permissions granted by custom role {name}. slots: name: path.name method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/custom_roles/{name}'].put update: x-apievangelist-phrasing: intent: Update a custom role effect: write questions: - Can I change the permissions on an existing custom role? - Is it possible to relabel a custom role without recreating it? instructions: - text: Update custom role {name} with description {description}. slots: name: path.name description: requestBody.description - text: Set permissions {permissions} on custom role {name}, description {description}. slots: permissions: requestBody.permissions name: path.name description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/custom_roles/{name}'].delete update: x-apievangelist-phrasing: intent: Delete a custom role effect: destructive questions: - How do I delete a custom role? - Why can't I delete a custom role that is still assigned to a user or service account? instructions: - text: Delete custom role {name}. slots: name: path.name - text: Remove the unassigned custom role {name}. slots: name: path.name method: generated generated: '2026-10-01'