# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for config-service Data Security Onboarding API version: 1.0.0 extends: openapi/palo-alto-networks-data-security-onboarding-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 6 - target: $.paths['/config/v3/account/storageUUID/{id}'].get update: x-apievangelist-phrasing: intent: Get data security account config by storage UUID effect: read questions: - Which data security account config belongs to a given storage UUID? - Can I look up a PCDS account when I only have its storage UUID? instructions: - text: Fetch the account config for storage UUID {id}. slots: id: path.id - text: Show the data security account tied to storage {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/config/v3/account/{id}'].get update: x-apievangelist-phrasing: intent: Get data security account config by account ID effect: read questions: - What is the onboarding config for a specific PCDS account? - Can I pre-initialize an account for an Azure subscription while fetching its config? instructions: - text: Fetch the account config for PCDS account {id}. slots: id: path.id - text: Get PCDS account {id} config with initialize set to {initialize} for the Azure flow. slots: id: path.id initialize: query.initialize method: generated generated: '2026-09-26' - target: $.paths['/config/v3/account/{id}'].put update: x-apievangelist-phrasing: intent: Update a data security account config effect: write questions: - Can I change the scan option for a data security onboarded account? - Is it possible to rename a PCDS account's config? instructions: - text: Update PCDS account {id} to scan option {scanOption}. slots: id: path.id scanOption: requestBody.scanOption - text: Rename data security account {id} to {accountName}. slots: id: path.id accountName: requestBody.accountName method: generated generated: '2026-09-26' - target: $.paths['/config/v3/account/{id}/status'].get update: x-apievangelist-phrasing: intent: Check a data security account's permissions effect: read questions: - Is my data security account missing any cloud permissions? - Why is data scanning failing on an onboarded account's permissions check? instructions: - text: Run the permissions check for PCDS account {id}. slots: id: path.id - text: Show missing permissions for data security account {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/config/v3/account/{subscriptionId}/acl-script'].get update: x-apievangelist-phrasing: intent: Generate an Azure network ACL script effect: read questions: - How can I fix network connectivity issues for data security scanning in Azure? - Can I get a network ACL script for my Azure subscription? instructions: - text: Generate the Azure network ACL script for subscription {subscriptionId}. slots: subscriptionId: path.subscriptionId - text: Get the ACL fix script for Azure subscription {subscriptionId}. slots: subscriptionId: path.subscriptionId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/tenant/{tenantId}/{subscriptionId}/terraform-script'].get update: x-apievangelist-phrasing: intent: Generate an Azure onboarding Terraform script effect: read questions: - Where do I get a Terraform script with all permissions needed to onboard Azure for data security? - Can I generate onboarding Terraform for a specific tenant and subscription? instructions: - text: Generate the Azure Terraform script for tenant {tenantId} and subscription {subscriptionId}. slots: tenantId: path.tenantId subscriptionId: path.subscriptionId - text: Get the permissions Terraform for Azure subscription {subscriptionId} under tenant {tenantId}. slots: subscriptionId: path.subscriptionId tenantId: path.tenantId method: generated generated: '2026-09-26'