# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Data Security Settings API version: 1.0.0 extends: openapi/palo-alto-networks-data-security-settings-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 39 - target: $.paths['/dlp/api/v1/resource-inventory/resources'].get update: x-apievangelist-phrasing: intent: List S3 buckets in the data resource inventory effect: read questions: - Which of my onboarded AWS S3 buckets are in the Prisma Cloud data resource inventory? - How much data in each S3 bucket is eligible for a sensitive data scan? instructions: - text: List every S3 bucket resource in my data security resource inventory. - text: Show how much scan-eligible data each onboarded S3 bucket holds. method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/config/v2/resource'].put update: x-apievangelist-phrasing: intent: Turn data scanning on or off for resources effect: write questions: - Can I enable sensitive data scanning for a specific set of S3 resources through the v2 resource config? - How do I stop data security scans on buckets I no longer want scanned? instructions: - text: Set data scanning to {enableScanning} for resources {resources} using the v2 resource config. slots: enableScanning: requestBody.enableScanning resources: requestBody.resources - text: Enable {scanType} scanning with scan option {scanOption} on resources {resources} via the older v2 endpoint. slots: scanType: requestBody.scanType scanOption: requestBody.scanOption resources: requestBody.resources method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-pattern'].put update: x-apievangelist-phrasing: intent: Filter my data patterns by mode and editor effect: read questions: - Can I list only the custom data patterns someone updated in a given time range? - Which data patterns in my own tenant were last updated by a particular user? instructions: - text: List my data patterns filtered to mode {modeFilter}. slots: modeFilter: requestBody.modeFilter - text: Show data patterns updated by {updatedByFilter} within {timeRange}. slots: updatedByFilter: requestBody.updatedByFilter timeRange: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-pattern'].post update: x-apievangelist-phrasing: intent: Create a data pattern in my tenant effect: write questions: - How do I define a new regex-based data pattern for sensitive data detection? - Can a new data pattern use proximity keywords to cut false positives? instructions: - text: Create data pattern {name} described as {description} using regexes {regexes}. slots: name: requestBody.name description: requestBody.description regexes: requestBody.regexes - text: Add a data pattern {name} with detection technique {detectionTechnique} and proximity keywords {proximityKeywords}. slots: name: requestBody.name detectionTechnique: requestBody.detectionTechnique proximityKeywords: requestBody.proximityKeywords method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-pattern/clone'].post update: x-apievangelist-phrasing: intent: Clone a data pattern in my tenant effect: write questions: - Can I copy an existing predefined data pattern so I can tweak its confidence levels? - What do I need to send to duplicate a data pattern under a new name? instructions: - text: Clone data pattern {id} as {name}. slots: id: requestBody.id name: requestBody.name - text: Copy pattern {id} into a new pattern {name} with confidence levels {confidenceLevels}. slots: id: requestBody.id name: requestBody.name confidenceLevels: requestBody.confidenceLevels method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-pattern/id/{patternId}'].get update: x-apievangelist-phrasing: intent: Get one data pattern's details effect: read questions: - What regexes and detection technique does a particular data pattern use? - How can I look up the full definition of a data pattern by its ID? instructions: - text: Show the details of data pattern {patternId}. slots: patternId: path.patternId - text: Get the regexes and keywords configured on pattern {patternId}. slots: patternId: path.patternId method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-pattern/name'].get update: x-apievangelist-phrasing: intent: List data pattern names and confidence levels effect: read questions: - Which data pattern names exist in my tenant and what confidence levels does each support? - Is there a lightweight list of just the data pattern names? instructions: - text: List all data pattern names with their supported confidence levels. - text: Give me the names of every data pattern I can reference in a profile. method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-pattern/{patternId}'].put update: x-apievangelist-phrasing: intent: Update a data pattern in my tenant effect: write questions: - Can I change the regexes on a custom data pattern I already created? - How do I rename or re-describe an existing data pattern? instructions: - text: Update data pattern {patternId} to use regexes {regexes}. slots: patternId: path.patternId regexes: requestBody.regexes - text: Rename data pattern {patternId} to {name} with description {description}. slots: patternId: path.patternId name: requestBody.name description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-pattern/{patternId}'].delete update: x-apievangelist-phrasing: intent: Delete a data pattern from my tenant effect: destructive questions: - How do I remove a custom data pattern I no longer need? - Does deleting a data pattern by ID remove it permanently? instructions: - text: Delete data pattern {patternId}. slots: patternId: path.patternId - text: Remove the data pattern with ID {patternId} from my tenant. slots: patternId: path.patternId method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-profile'].get update: x-apievangelist-phrasing: intent: List data profiles in my tenant effect: read questions: - What data profiles are configured for my tenant? - Which DLP data profiles exist right now, both predefined and custom? instructions: - text: List all data profiles for my tenant. - text: Show every data profile I have configured. method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-profile'].put update: x-apievangelist-phrasing: intent: Enable or disable data profiles effect: write questions: - Can I switch several data profiles off at once without deleting them? - How do I re-enable a data profile I disabled earlier? instructions: - text: Disable the data profiles I no longer want applied. - text: Enable the selected data profiles again in my tenant. method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-profile'].post update: x-apievangelist-phrasing: intent: Create a data profile in my tenant effect: write questions: - How do I build a data profile that groups several data patterns into one rule? - What fields does a new custom data profile require? instructions: - text: Create data profile {name} with pattern rule {dataPatternsRule1}. slots: name: requestBody.name dataPatternsRule1: requestBody.dataPatternsRule1 - text: Add a {profileType} data profile named {name} with status {profileStatus}. slots: profileType: requestBody.profileType name: requestBody.name profileStatus: requestBody.profileStatus method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-profile/id/{profileId}'].get update: x-apievangelist-phrasing: intent: Get one data profile's details effect: read questions: - Which data patterns are included in a particular data profile? - How can I see the rules of a data profile by its ID? instructions: - text: Show the details of data profile {profileId}. slots: profileId: path.profileId - text: Get the pattern rules inside profile {profileId}. slots: profileId: path.profileId method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-profile/id/{profileId}'].put update: x-apievangelist-phrasing: intent: Update a data profile in my tenant effect: write questions: - Can I add more data patterns to an existing data profile's rule? - How do I change the name or status of a data profile I already have? instructions: - text: Update data profile {profileId} to use pattern rule {dataPatternsRule1}. slots: profileId: path.profileId dataPatternsRule1: requestBody.dataPatternsRule1 - text: Rename data profile {profileId} to {name}. slots: profileId: path.profileId name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-profile/id/{profileId}'].post update: x-apievangelist-phrasing: intent: Clone a data profile in my tenant effect: write questions: - Can I duplicate a predefined data profile to customize it? - Is there a quick way to copy a data profile by its ID? instructions: - text: Clone data profile {profileId}. slots: profileId: path.profileId - text: Make a copy of profile {profileId} that I can edit. slots: profileId: path.profileId method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/data-profile/id/{profileId}'].delete update: x-apievangelist-phrasing: intent: Delete a data profile from my tenant effect: destructive questions: - How do I get rid of a custom data profile? - What happens when I delete a data profile by ID? instructions: - text: Delete data profile {profileId}. slots: profileId: path.profileId - text: Remove profile {profileId} from my tenant. slots: profileId: path.profileId method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/snippets'].get update: x-apievangelist-phrasing: intent: Get my snippet masking settings effect: read questions: - Are data snippets enabled for my tenant, and at what masking level? - What is my current snippet masking configuration? instructions: - text: Show my tenant's snippet masking configuration. - text: Check whether sensitive data snippets are enabled for me. method: generated generated: '2026-09-26' - target: $.paths['/dlp/api/v1/dss-api/snippets'].post update: x-apievangelist-phrasing: intent: Change my snippet masking settings effect: write questions: - Can I turn off sensitive data snippets entirely for my tenant? - How do I switch snippets to full masking? instructions: - text: Set snippets enabled to {snippetsEnabled} with mask level {maskLevel}. slots: snippetsEnabled: requestBody.snippetsEnabled maskLevel: requestBody.maskLevel - text: Change my snippet mask level to {maskLevel} and keep snippets enabled {snippetsEnabled}. slots: maskLevel: requestBody.maskLevel snippetsEnabled: requestBody.snippetsEnabled method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-pattern/clone/dssTenantId/{dssTenantId}'].post update: x-apievangelist-phrasing: intent: Clone a data pattern for a DSS tenant effect: write questions: - Can I clone a data pattern inside a specific DSS tenant using the v3 config API? - How is a data pattern copied when I address the tenant by its DSS tenant ID? instructions: - text: Clone a data pattern in DSS tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId - text: Duplicate a pattern under DSS tenant {dssTenantId} with the v3 endpoint. slots: dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-pattern/dssTenantId/{dssTenantId}'].get update: x-apievangelist-phrasing: intent: List data patterns for a DSS tenant effect: read questions: - Which data patterns does a given DSS tenant ID have? - Can I fetch every data pattern for a tenant by passing its DSS tenant ID? instructions: - text: List all data patterns in DSS tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId - text: Show the v3 data pattern list for tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-pattern/dssTenantId/{dssTenantId}'].post update: x-apievangelist-phrasing: intent: Create a data pattern for a DSS tenant effect: write questions: - How do I add a new data pattern to a specific DSS tenant with the v3 API? - Can I create data patterns for a tenant other than the one in my token? instructions: - text: Create a new data pattern in DSS tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId - text: Add a v3 data pattern for tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-pattern/dssTenantId/{dssTenantId}/pattern-id/{patternId}'].put update: x-apievangelist-phrasing: intent: Update a data pattern in a DSS tenant effect: write questions: - Can I edit a data pattern by pattern ID inside a named DSS tenant? - What's the v3 way to modify a pattern for a specific tenant? instructions: - text: Update pattern {patternId} in DSS tenant {dssTenantId}. slots: patternId: path.patternId dssTenantId: path.dssTenantId - text: Edit v3 data pattern {patternId} for tenant {dssTenantId}. slots: patternId: path.patternId dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-pattern/dssTenantId/{dssTenantId}/pattern-id/{patternId}'].delete update: x-apievangelist-phrasing: intent: Delete a data pattern from a DSS tenant effect: destructive questions: - How do I delete a pattern from a particular DSS tenant? - Can a v3 data pattern be removed by tenant ID and pattern ID together? instructions: - text: Delete pattern {patternId} from DSS tenant {dssTenantId}. slots: patternId: path.patternId dssTenantId: path.dssTenantId - text: Remove v3 data pattern {patternId} in tenant {dssTenantId}. slots: patternId: path.patternId dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-pattern/name/dssTenantId/{dssTenantId}'].get update: x-apievangelist-phrasing: intent: List pattern names for a DSS tenant effect: read questions: - What pattern names and confidence levels are available in a given DSS tenant? - Can I get only the data pattern names for a tenant by its DSS ID? instructions: - text: List data pattern names with confidence levels for DSS tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId - text: Give me the v3 pattern name list for tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-profile/dssTenantId/{dssTenantId}'].get update: x-apievangelist-phrasing: intent: List data profiles for a DSS tenant effect: read questions: - Which data profiles belong to a specific DSS tenant? - Can I list profiles for a tenant using its DSS tenant ID? instructions: - text: List all data profiles in DSS tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId - text: Show the v3 data profiles for tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-profile/dssTenantId/{dssTenantId}'].put update: x-apievangelist-phrasing: intent: Enable or disable profiles in a DSS tenant effect: write questions: - Can I toggle data profiles on or off for a particular DSS tenant? - What's the v3 call to bulk-disable profiles for one tenant? instructions: - text: Disable the chosen data profiles in DSS tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId - text: Enable data profiles again for tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-profile/dssTenantId/{dssTenantId}'].post update: x-apievangelist-phrasing: intent: Create a data profile for a DSS tenant effect: write questions: - How do I create a data profile inside a specific DSS tenant? - Can a v3 data profile be created with a pattern rule and profile type? instructions: - text: Create data profile {name} in DSS tenant {dssTenantId}. slots: name: requestBody.name dssTenantId: path.dssTenantId - text: Add a {profileType} profile {name} with rule {rule} to tenant {dssTenantId}. slots: profileType: requestBody.profile_type name: requestBody.name rule: requestBody.data_patterns_rule_1 dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-profile/dssTenantId/{dssTenantId}/id/{profileId}'].get update: x-apievangelist-phrasing: intent: Get a data profile in a DSS tenant effect: read questions: - What does a given data profile contain in a specific DSS tenant? - Can I fetch one v3 profile by tenant ID and profile ID? instructions: - text: Show data profile {profileId} in DSS tenant {dssTenantId}. slots: profileId: path.profileId dssTenantId: path.dssTenantId - text: Get the rules of v3 profile {profileId} for tenant {dssTenantId}. slots: profileId: path.profileId dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-profile/dssTenantId/{dssTenantId}/id/{profileId}'].put update: x-apievangelist-phrasing: intent: Update a data profile in a DSS tenant effect: write questions: - Can I change a data profile's status within a particular DSS tenant? - How do I edit a v3 data profile's pattern rule? instructions: - text: Update profile {profileId} in DSS tenant {dssTenantId} with rule {rule}. slots: profileId: path.profileId dssTenantId: path.dssTenantId rule: requestBody.data_patterns_rule_1 - text: Set the status of v3 profile {profileId} in tenant {dssTenantId} to {profileStatus}. slots: profileId: path.profileId dssTenantId: path.dssTenantId profileStatus: requestBody.profile_status method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-profile/dssTenantId/{dssTenantId}/id/{profileId}'].post update: x-apievangelist-phrasing: intent: Clone a data profile in a DSS tenant effect: write questions: - Can I duplicate a profile that lives in a specific DSS tenant? - What's the v3 call to copy a data profile by ID? instructions: - text: Clone profile {profileId} in DSS tenant {dssTenantId}. slots: profileId: path.profileId dssTenantId: path.dssTenantId - text: Copy v3 data profile {profileId} for tenant {dssTenantId}. slots: profileId: path.profileId dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/data-profile/dssTenantId/{dssTenantId}/id/{profileId}'].delete update: x-apievangelist-phrasing: intent: Delete a data profile from a DSS tenant effect: destructive questions: - How do I delete a profile from one particular DSS tenant? - Is a v3 data profile removed permanently when deleted? instructions: - text: Delete profile {profileId} from DSS tenant {dssTenantId}. slots: profileId: path.profileId dssTenantId: path.dssTenantId - text: Remove v3 data profile {profileId} in tenant {dssTenantId}. slots: profileId: path.profileId dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/snippets/dssTenantId/{dssTenantId}'].get update: x-apievangelist-phrasing: intent: Get snippet masking for a DSS tenant effect: read questions: - What snippet masking level is set for a specific DSS tenant? - Are snippets on for the tenant with a given DSS ID? instructions: - text: Show the snippet masking configuration for DSS tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId - text: Check v3 snippet settings for tenant {dssTenantId}. slots: dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/dss-api/snippets/dssTenantId/{dssTenantId}'].post update: x-apievangelist-phrasing: intent: Change snippet masking for a DSS tenant effect: write questions: - Can I change snippet masking for a specific DSS tenant rather than my own? - How do I disable snippets for one tenant through the v3 API? instructions: - text: Set snippet mask level to {maskLevel} for DSS tenant {dssTenantId}. slots: maskLevel: requestBody.maskLevel dssTenantId: path.dssTenantId - text: Turn snippets {snippetsEnabled} for tenant {dssTenantId} via v3. slots: snippetsEnabled: requestBody.snippetsEnabled dssTenantId: path.dssTenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/estimated-credits'].post update: x-apievangelist-phrasing: intent: Estimate scan credits for resources effect: read questions: - How many credits would scanning these cloud storage resources cost? - What's the total data volume of the resources I plan to scan? instructions: - text: Estimate the credits needed to scan resources {resources}. slots: resources: requestBody.resources - text: Calculate data volume and credits for a {scanType} scan of {resources}. slots: scanType: requestBody.scanType resources: requestBody.resources method: generated generated: '2026-09-26' - target: $.paths['/config/v3/resource/configure'].put update: x-apievangelist-phrasing: intent: Update resource scan settings (v3) effect: write questions: - Can I change the scan type and option on many resources in one v3 configure call? - Which resource scan configs come back after I update them? instructions: - text: Configure resources {resources} with scan type {scanType} using the v3 configure endpoint. slots: resources: requestBody.resources scanType: requestBody.scanType - text: Set scanning to {enableScanning} on {resources} through v3 resource configure. slots: enableScanning: requestBody.enableScanning resources: requestBody.resources method: generated generated: '2026-09-26' - target: $.paths['/config/v3/resources'].get update: x-apievangelist-phrasing: intent: List all resources for my PCDS tenant effect: read questions: - What resources are tied to my PCDS tenant across all clouds? - Can I pull every data security resource linked to the tenant in my access token? instructions: - text: Fetch all resources for my PCDS tenant. - text: List every resource attached to the PCDS tenant in my token. method: generated generated: '2026-09-26' - target: $.paths['/config/v3/tenant/acl-script'].get update: x-apievangelist-phrasing: intent: Generate an Azure network ACL Terraform script effect: read questions: - Can I get a Terraform script that fixes network connectivity for my Azure accounts? - What Azure network ACL changes are needed so data scans can reach my storage? instructions: - text: Generate the Azure network ACL Terraform script for all my PCDS tenant's Azure accounts. - text: Give me a Terraform script to fix Azure network access for data scanning. method: generated generated: '2026-09-26' - target: $.paths['/config/v3/tenant/config'].get update: x-apievangelist-phrasing: intent: Get the PCDS tenant configuration effect: read questions: - What configuration is set on my PCDS tenant? - Can I look up tenant config details for a specific tenant ID? instructions: - text: Show my PCDS tenant configuration. - text: Get the tenant config for tenant {tenantId}. slots: tenantId: query.tenantId method: generated generated: '2026-09-26' - target: $.paths['/config/v3/tenant/resource/sizing/configure'].put update: x-apievangelist-phrasing: intent: Set the resource size reporting frequency effect: write questions: - How often does the tenant report resource sizes, and can I change it? - Can I set a global size reporting frequency for all tenant resources? instructions: - text: Set the resource size reporting frequency to {sizeReportingFrequency}. slots: sizeReportingFrequency: requestBody.sizeReportingFrequency - text: Change how often my tenant's resource sizes are reported. method: generated generated: '2026-09-26'