# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Incident Security Service Posture Management IDP API version: 1.0.0 extends: openapi/palo-alto-networks-idp-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 11 - target: $.paths['/sspm/identity/v1/idps'].get update: x-apievangelist-phrasing: intent: List the tenant's identity providers effect: read questions: - Which identity providers are connected to my SaaS security posture tenant? - Can I see only the designated identity providers? instructions: - text: List all identity providers configured for tenant {x-ps-tenant}. slots: x-ps-tenant: header.x-ps-tenant - text: Show only identity providers where designated is {designated}. slots: designated: query.designated method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps'].post update: x-apievangelist-phrasing: intent: Register a new identity provider effect: write questions: - How do I add an identity provider to my SSPM tenant? - Can a new identity provider be marked as designated when I add it? instructions: - text: Add identity provider {idpId} of type {idpType}. slots: idpId: query.idpId idpType: query.idpType - text: Register a {idpType} identity provider and mark it designated={designated}. slots: idpType: query.idpType designated: query.designated method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].get update: x-apievangelist-phrasing: intent: Check the status of a forced account logout effect: read questions: - Did the forced logout of accounts on my identity provider finish? - What is the outcome of a specific logout batch I triggered earlier? instructions: - text: Check logout status for identity provider {idpId}, batch {batch_id}. slots: idpId: path.idpId batch_id: query.batch_id - text: Show the result of the account logout run on identity provider {idpId}. slots: idpId: path.idpId method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].post update: x-apievangelist-phrasing: intent: Force-log out users from an identity provider effect: destructive questions: - How can I terminate sessions for compromised users in my identity provider? - Can I sign out a specific list of users from one identity provider at once? instructions: - text: Log out users {users} from identity provider {idpId}. slots: users: requestBody.users idpId: path.idpId - text: Force session termination for the listed accounts on identity provider {idpId}. slots: idpId: path.idpId method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/feature_state'].get update: x-apievangelist-phrasing: intent: Check an identity provider feature's scan state effect: read questions: - When was a feature on my identity provider last scanned, and is it healthy? - What is the current state of a given feature for one identity provider? instructions: - text: Get the state and last scan time of feature {feature} on identity provider {idpId}. slots: feature: query.feature idpId: path.idpId - text: Show feature health for identity provider {idpId}. slots: idpId: path.idpId method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/count'].get update: x-apievangelist-phrasing: intent: Count accounts on an identity provider effect: read questions: - How many user accounts are linked to my identity provider? - Can I count just the orphaned or privileged accounts in an identity provider? instructions: - text: Count the accounts on identity provider {idpId}. slots: idpId: path.idpId - text: Count accounts on identity provider {idpId} matching filter {filter}. slots: idpId: path.idpId filter: query.filter method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/csv_report'].post update: x-apievangelist-phrasing: intent: Generate a CSV report of identity provider accounts effect: write questions: - Can I export the user accounts in my identity provider to CSV for an access review? - Who receives the identity provider account report once it is generated? instructions: - text: Generate an account CSV for identity provider {idpId} and send it to {userFullName} at {userEmail} for service {service}. slots: idpId: path.idpId userFullName: requestBody.userFullName userEmail: requestBody.userEmail service: requestBody.service - text: Build a CSV of accounts on identity provider {idpId} sorted by {sortBy}. slots: idpId: path.idpId sortBy: query.sortBy method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity'].get update: x-apievangelist-phrasing: intent: View MFA activity logs for an identity provider effect: read questions: - What multi-factor authentication events has my identity provider recorded, with user and IP? - Can I page through MFA logs sorted by time? instructions: - text: Show MFA activity for identity provider {idpId}. slots: idpId: path.idpId - text: List MFA events on identity provider {idpId} matching {filter}, page {page}. slots: idpId: path.idpId filter: query.filter page: query.page method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count'].get update: x-apievangelist-phrasing: intent: Count MFA events on an identity provider effect: read questions: - How many multi-factor authentication events happened on my identity provider? - What is the total MFA volume matching a filter? instructions: - text: Count MFA events for identity provider {idpId}. slots: idpId: path.idpId - text: Give me the number of MFA events on identity provider {idpId} that match {filter}. slots: idpId: path.idpId filter: query.filter method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count_by_app_type'].get update: x-apievangelist-phrasing: intent: Break down MFA activity by application type effect: read questions: - Which application types generate the most MFA prompts on my identity provider? - Is there a per-app-type breakdown of multi-factor authentication activity? instructions: - text: Break down MFA activity by app type for identity provider {idpId}. slots: idpId: path.idpId - text: Group MFA counts by application type on identity provider {idpId} using filter {filter}. slots: idpId: path.idpId filter: query.filter method: generated generated: '2026-09-26' - target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/csv_report'].post update: x-apievangelist-phrasing: intent: Generate a CSV report of MFA activity effect: write questions: - Can I export multi-factor authentication activity to a CSV for auditors? - What details do I have to supply to request an MFA activity report? instructions: - text: Generate an MFA activity CSV for identity provider {idpId}, addressed to {userFullName} at {userEmail} for service {service}. slots: idpId: path.idpId userFullName: requestBody.userFullName userEmail: requestBody.userEmail service: requestBody.service - text: Export MFA events on identity provider {idpId} matching {filter} to CSV. slots: idpId: path.idpId filter: query.filter method: generated generated: '2026-09-26'