# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks IAM API version: 1.0.0 extends: openapi/palo-alto-networks-iam-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 21 - target: $.paths['/api/v1/permission'].post update: x-apievangelist-phrasing: intent: Run an IAM query to list permissions effect: read questions: - How do I run an IAM query in Prisma Cloud to see who can access what? - Can I cap how many permission results the original IAM permission search returns? instructions: - text: Run IAM query {query} and return the first {limit} permissions. slots: query: requestBody.query limit: requestBody.limit - text: Execute the v1 IAM permission query {query} with a limit of {limit}. slots: query: requestBody.query limit: requestBody.limit method: generated generated: '2026-09-26' - target: $.paths['/api/v1/permission/page'].post update: x-apievangelist-phrasing: intent: Get the next page of IAM permission results effect: read questions: - What do I pass to fetch the next page after a v1 IAM permissions query? - Can I page through more permission rows using the token from my last query? instructions: - text: Fetch the next page of permissions using page token {pageToken}. slots: pageToken: requestBody.pageToken - text: Continue the v1 permissions results from token {pageToken}, {limit} rows at a time. slots: pageToken: requestBody.pageToken limit: requestBody.limit method: generated generated: '2026-09-26' - target: $.paths['/api/v1/permission/access'].post update: x-apievangelist-phrasing: intent: See when a permission was last used effect: read questions: - How can I tell when a specific IAM permission was actually last used? - Is there a way to see last-access data for one permission ID under an IAM query? instructions: - text: Show last-access usage for permission {permissionId} under query {query}. slots: permissionId: requestBody.permissionId query: requestBody.query - text: Get up to {limit} last-access records for permission {permissionId} matching {query}. slots: limit: requestBody.limit permissionId: requestBody.permissionId query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/api/v1/permission/access/page'].post update: x-apievangelist-phrasing: intent: Get the next page of permission last-access data effect: read questions: - How do I keep paging through permission last-access results in v1? - Can I continue a permission usage listing with the token it returned? instructions: - text: Get the next page of permission access records with token {pageToken}. slots: pageToken: requestBody.pageToken - text: Continue listing permission last-access data from token {pageToken}. slots: pageToken: requestBody.pageToken method: generated generated: '2026-09-26' - target: $.paths['/api/v1/permission/alert/remediation'].post update: x-apievangelist-phrasing: intent: Get remediations for IAM alerts effect: read questions: - How do I get suggested remediations for a batch of IAM alerts? - Can I fetch fixes for several alert IDs in a single call? instructions: - text: Get remediations for alerts {alerts}. slots: alerts: requestBody.alerts - text: List the remediation steps for IAM alert IDs {alerts}. slots: alerts: requestBody.alerts method: generated generated: '2026-09-26' - target: $.paths['/api/v1/permission/alert/search'].get update: x-apievangelist-phrasing: intent: Get the IAM query behind an alert effect: read questions: - Which IAM query triggered a given alert, using the original v1 lookup? - Can I see the RQL an IAM alert was raised from by passing its alert ID as a query parameter? instructions: - text: Show the IAM query for alert {alertId} with the v1 search endpoint. slots: alertId: query.alertId - text: Look up the RQL behind alert {alertId}. slots: alertId: query.alertId method: generated generated: '2026-09-26' - target: $.paths['/api/v1/suggest'].post update: x-apievangelist-phrasing: intent: Get autocomplete suggestions for an IAM query effect: read questions: - How can I tell whether my partial IAM query is valid yet? - What can I append to a half-written IAM query to complete it in the v1 suggest endpoint? instructions: - text: Suggest completions for the partial IAM query {query}. slots: query: requestBody.query - text: Check if {query} is a valid IAM query and suggest what comes next. slots: query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v3/search/permission'].post update: x-apievangelist-phrasing: intent: Search IAM permissions with the v3 API effect: read questions: - How do I search permissions with the v3 IAM search and get a next page token? - Can I limit the page size when searching permissions in v3? instructions: - text: Search permissions in v3 with query {query}. slots: query: requestBody.query - text: Run v3 permission search {query}, {limit} per page, continuing from token {nextPageToken}. slots: query: requestBody.query limit: query.limit nextPageToken: requestBody.nextPageToken method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v4/search/permission'].post update: x-apievangelist-phrasing: intent: Search permissions grouped by fields (v4) effect: read questions: - Can I group IAM permission search results by specific fields? - What does the v4 permission search return compared to a flat list? instructions: - text: Search permissions with query {query} grouped by {groupByFields}. slots: query: requestBody.query groupByFields: requestBody.groupByFields - text: Run a v4 grouped permission search for {query}. slots: query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v3/permission/{permission-id}/list_access'].post update: x-apievangelist-phrasing: intent: List last accesses of a permission (v3) effect: read questions: - How do I list the recent accesses for one permission ID in the v3 API? - Can I page through a permission's last-access history with a token? instructions: - text: List v3 last accesses for permission {permission_id} filtered by {query}. slots: permission_id: path.permission-id query: requestBody.query - text: Get the next {limit} accesses of permission {permission_id} from token {nextPageToken}. slots: limit: query.limit permission_id: path.permission-id nextPageToken: requestBody.nextPageToken method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v2/suggestion'].post update: x-apievangelist-phrasing: intent: Autocomplete an RQL query (v2) effect: read questions: - Is there a newer suggestion endpoint that autocompletes RQL and flags invalid queries? - How do I get v2 autocomplete hints for the RQL I'm typing? instructions: - text: Autocomplete RQL {query} using v2 suggestions. slots: query: requestBody.query - text: Tell me whether RQL {query} is valid via the v2 suggestion service. slots: query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v2/search/iam_config'].post update: x-apievangelist-phrasing: intent: Get the raw role or policy behind a permission effect: read questions: - Can I see the raw policy or role definition a permission was calculated from? - Where does a given IAM permission come from in the underlying config? instructions: - text: Show the raw policy or role definition for permission {permissionId}. slots: permissionId: requestBody.permissionId - text: Get the source IAM config for permission {permissionId}. slots: permissionId: requestBody.permissionId method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v1/asset/{asset-id}/related-asset'].post update: x-apievangelist-phrasing: intent: List assets related to a cloud identity effect: read questions: - What other assets are related to a Cloud Identity Inventory resource? - Can I filter an identity's related assets by relationship type and last access time? instructions: - text: List assets related to identity asset {asset_id}. slots: asset_id: path.asset-id - text: Show {relationshipType} related assets for {asset_id} accessed after {lastAccessFromTime}. slots: relationshipType: requestBody.relationshipType asset_id: path.asset-id lastAccessFromTime: requestBody.lastAccessFromTime method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v2/alert/{alertId}/remediation_command'].get update: x-apievangelist-phrasing: intent: Get the remediation command for an alert effect: read questions: - Is there a ready-made CLI command to remediate a specific IAM alert? - How do I get the fix command for one alert ID? instructions: - text: Get the remediation command for alert {alertId}. slots: alertId: path.alertId - text: Give me the command that fixes alert {alertId}. slots: alertId: path.alertId method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v2/alert/{alertId}/query'].get update: x-apievangelist-phrasing: intent: Get the query for an alert instance (v2) effect: read questions: - How do I investigate an alert by pulling the query tied to that alert instance in v2? - Can I get the v2 IAM query associated with an alert from its path ID? instructions: - text: Get the v2 query associated with alert {alertId}. slots: alertId: path.alertId - text: Investigate alert {alertId} by retrieving its IAM query. slots: alertId: path.alertId method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v1/assets/{assetId}/over-permissive-metadata'].get update: x-apievangelist-phrasing: intent: Check least-privilege potential for an asset effect: read questions: - Is this asset over-permissive, and how much could least privilege improve it? - What metadata is available about least-privilege improvement for an asset? instructions: - text: Show least-privilege improvement metadata for asset {assetId}. slots: assetId: path.assetId - text: Check whether asset {assetId} is over-permissive. slots: assetId: path.assetId method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v1/assets/{assetId}/existing-least-privileged-access'].get update: x-apievangelist-phrasing: intent: Suggest least privilege from existing roles for an asset effect: read questions: - Can I right-size an asset's access using only roles and policies that already exist? - How many days of activity does the existing-roles least-privilege suggestion look back over? instructions: - text: Suggest least privilege for asset {assetId} from existing policies over the last {lookback_duration_days} days as {output_format}. slots: assetId: path.assetId lookback_duration_days: query.lookback_duration_days output_format: query.output_format - text: Recommend existing roles for asset {assetId}, {lookback_duration_days}-day lookback, {output_format} output. slots: assetId: path.assetId lookback_duration_days: query.lookback_duration_days output_format: query.output_format method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v1/assets/{assetId}/custom-least-privileged-access'].get update: x-apievangelist-phrasing: intent: Generate a custom least-privilege policy for an asset effect: read questions: - Can Prisma Cloud generate a brand-new least-privilege policy for an asset? - Which output formats can a custom least-privilege config for an asset come in? instructions: - text: Generate a custom least-privilege config for asset {assetId} from {lookback_duration_days} days of use in {output_format}. slots: assetId: path.assetId lookback_duration_days: query.lookback_duration_days output_format: query.output_format - text: Create a new tailored policy for asset {assetId} covering {lookback_duration_days} days, format {output_format}. slots: assetId: path.assetId lookback_duration_days: query.lookback_duration_days output_format: query.output_format method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v1/resources/{resourceId}/over-permissive-metadata'].get update: x-apievangelist-phrasing: intent: Check least-privilege potential for a resource effect: read questions: - Does a particular cloud resource have room for access optimization? - Where can I see over-permissive metadata keyed by resource ID rather than asset ID? instructions: - text: Show over-permissive metadata for resource {resourceId}. slots: resourceId: path.resourceId - text: Check if resource {resourceId} could have its access tightened. slots: resourceId: path.resourceId method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v1/resources/{resourceId}/existing-least-privileged-access'].get update: x-apievangelist-phrasing: intent: Suggest least privilege from existing roles for a resource effect: read questions: - Can I tighten a resource's access by reusing its current IAM configurations? - How do I get existing-policy least-privilege suggestions by resource ID? instructions: - text: Suggest existing-role least privilege for resource {resourceId} over {lookback_duration_days} days in {output_format}. slots: resourceId: path.resourceId lookback_duration_days: query.lookback_duration_days output_format: query.output_format - text: Recommend current policies to keep for resource {resourceId}, lookback {lookback_duration_days} days, as {output_format}. slots: resourceId: path.resourceId lookback_duration_days: query.lookback_duration_days output_format: query.output_format method: generated generated: '2026-09-26' - target: $.paths['/iam/api/v1/resources/{resourceId}/custom-least-privileged-access'].get update: x-apievangelist-phrasing: intent: Generate a custom least-privilege policy for a resource effect: read questions: - Can I generate a new custom least-privilege config for a specific resource? - What would a tailored minimal policy look like for a resource based on recent actions? instructions: - text: Generate a custom least-privilege policy for resource {resourceId} from {lookback_duration_days} days in {output_format}. slots: resourceId: path.resourceId lookback_duration_days: query.lookback_duration_days output_format: query.output_format - text: Build a new minimal access config for resource {resourceId}, {lookback_duration_days}-day window, {output_format} format. slots: resourceId: path.resourceId lookback_duration_days: query.lookback_duration_days output_format: query.output_format method: generated generated: '2026-09-26'