# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Policies API version: 1.0.0 extends: openapi/palo-alto-networks-policies-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 166 - target: $.paths['/code/api/v1/policies/definition/{queryId}'].post update: x-apievangelist-phrasing: intent: Validate a YAML code policy definition effect: read questions: - Can I check that my YAML build policy definition is valid before saving it? - What happens if my policy-as-code query has a syntax error? instructions: - text: Validate the YAML policy definition for query {queryId}. slots: queryId: path.queryId - text: Check whether code policy query {queryId} is well formed. slots: queryId: path.queryId method: generated generated: '2026-09-26' - target: $.paths['/code/api/v1/policies'].post update: x-apievangelist-phrasing: intent: Save a new custom code policy effect: write questions: - How do I save a new YAML-based build policy in Prisma Cloud Application Security? - Can I add my own attribute or connection check as a custom code policy? instructions: - text: Save this YAML definition as a new custom build policy. - text: Create a new policy-as-code rule from my composite check. method: generated generated: '2026-09-26' - target: $.paths['/code/api/v1/policies/table/data'].get update: x-apievangelist-phrasing: intent: List custom code policies as a table effect: read questions: - Where can I see all the custom build policies I've written? - Which policy-as-code rules exist in my Application Security tenant? instructions: - text: Show the custom code policies table. - text: List every custom build policy with its table data. method: generated generated: '2026-09-26' - target: $.paths['/code/api/v1/policies/{policyId}'].put update: x-apievangelist-phrasing: intent: Update a custom YAML code policy effect: write questions: - Can I edit the YAML of a custom build policy I already saved? - How do I change the definition of an existing policy-as-code rule? instructions: - text: Update custom code policy {policyId} with my revised YAML. slots: policyId: path.policyId - text: Replace the build policy definition of {policyId}. slots: policyId: path.policyId method: generated generated: '2026-09-26' - target: $.paths['/code/api/v1/policies/{policyId}'].delete update: x-apievangelist-phrasing: intent: Delete a custom code policy effect: destructive questions: - How do I remove a custom build policy I no longer need? - Is deleting a policy-as-code rule permanent? instructions: - text: Delete custom code policy {policyId}. slots: policyId: path.policyId - text: Remove build policy {policyId} from Application Security. slots: policyId: path.policyId method: generated generated: '2026-09-26' - target: $.paths['/code/api/v1/policies/preview'].post update: x-apievangelist-phrasing: intent: Preview results of a code policy effect: read questions: - Can I see which resources a YAML build policy would flag before I save it? - What results would a Checkov check return if I previewed it? instructions: - text: Preview the results of this code policy, showing {resultsNumber} results. slots: resultsNumber: requestBody.resultsNumber - text: Run a preview of Checkov check {checkovCheckId}. slots: checkovCheckId: requestBody.checkovCheckId method: generated generated: '2026-09-26' - target: $.paths['/code/api/v1/policies/clone/{policyId}'].post update: x-apievangelist-phrasing: intent: Clone an existing code policy effect: write questions: - Can I copy an existing build policy and tweak it as my own? - How do I duplicate a code policy with a different severity? instructions: - text: Clone code policy {policyId} as a new custom policy. slots: policyId: path.policyId - text: Clone build policy {policyId} with title {title} and severity {severity}. slots: policyId: path.policyId title: requestBody.title severity: requestBody.severity method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/ci/images'].get update: x-apievangelist-phrasing: intent: Get the CI image compliance policy (v34.03) effect: read questions: - What compliance rules apply to images scanned in CI under API v34.03? - Can I read the continuous integration image compliance policy with the v34.03 API? instructions: - text: Get the CI image compliance policy using v34.03. - text: Show the v34.03 compliance rules for CI-scanned images. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/ci/images'].put update: x-apievangelist-phrasing: intent: Update the CI image compliance policy (v34.03) effect: write questions: - How do I change the compliance rules for CI image scans through v34.03? - Does the v34.03 update replace every CI image compliance rule at once? instructions: - text: Update the CI image compliance policy via v34.03 with these rules. - text: Replace the v34.03 CI image compliance rules with {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/ci/serverless'].get update: x-apievangelist-phrasing: intent: Get the CI serverless compliance policy (v34.03) effect: read questions: - Which compliance checks run on serverless functions in CI under v34.03? - Can I read the CI serverless compliance policy from the v34.03 endpoint? instructions: - text: Get the v34.03 CI serverless compliance policy. - text: Show compliance rules for functions scanned in CI (v34.03). method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/ci/serverless'].put update: x-apievangelist-phrasing: intent: Update the CI serverless compliance policy (v34.03) effect: write questions: - How do I edit the CI serverless compliance rules with the v34.03 API? - Can I push a new rule set for serverless CI compliance using v34.03? instructions: - text: Update the CI serverless compliance policy through v34.03. - text: Set the v34.03 CI serverless compliance rules to {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/container'].get update: x-apievangelist-phrasing: intent: Get the container compliance policy (v34.03) effect: read questions: - What compliance rules are enforced on running containers in v34.03? - Can I fetch the container compliance policy via the v34.03 API? instructions: - text: Get the container compliance policy with v34.03. - text: Show my v34.03 container compliance rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/container'].put update: x-apievangelist-phrasing: intent: Update the container compliance policy (v34.03) effect: write questions: - How do I change container compliance rules using v34.03? - Will a v34.03 container compliance update overwrite existing rules? instructions: - text: Update the container compliance policy via v34.03. - text: Replace v34.03 container compliance rules with {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/container/impacted'].get update: x-apievangelist-phrasing: intent: List containers impacted by a compliance rule (v34.03) effect: read questions: - Which containers are affected by a given compliance rule in v34.03? - Can I page through containers impacted by a compliance rule on v34.03? instructions: - text: List containers impacted by compliance rule {rule} using v34.03. slots: rule: query.ruleName - text: Show the first {limit} containers hit by compliance rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/host'].get update: x-apievangelist-phrasing: intent: Get the host compliance policy (v34.03) effect: read questions: - What compliance rules apply to my hosts under v34.03? - Can I read the host compliance policy through the v34.03 API? instructions: - text: Get the v34.03 host compliance policy. - text: Show host compliance rules from v34.03. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/host'].put update: x-apievangelist-phrasing: intent: Update the host compliance policy (v34.03) effect: write questions: - How do I update host compliance rules with v34.03? - Can I replace the whole host compliance rule set on v34.03? instructions: - text: Update the host compliance policy via v34.03. - text: Set v34.03 host compliance rules to {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/serverless'].get update: x-apievangelist-phrasing: intent: Get the serverless compliance policy (v34.03) effect: read questions: - Which compliance rules apply to deployed serverless functions in v34.03? - Can I fetch the serverless compliance policy on v34.03? instructions: - text: Get the serverless compliance policy using v34.03. - text: Show v34.03 compliance rules for deployed functions. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/serverless'].put update: x-apievangelist-phrasing: intent: Update the serverless compliance policy (v34.03) effect: write questions: - How do I change serverless function compliance rules via v34.03? - Can I overwrite the deployed-function compliance rules on v34.03? instructions: - text: Update the v34.03 serverless compliance policy. - text: Replace serverless compliance rules with {rules} on v34.03. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/compliance/vms/impacted'].get update: x-apievangelist-phrasing: intent: List VMs impacted by a compliance rule (v34.03) effect: read questions: - Which virtual machine images are affected by a compliance rule in v34.03? - Can I sort the VMs impacted by a compliance rule on v34.03? instructions: - text: List VMs impacted by compliance rule {rule} via v34.03. slots: rule: query.ruleName - text: Show {limit} VMs hit by compliance rule {rule} using v34.03. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/agentless'].get update: x-apievangelist-phrasing: intent: Get the agentless app firewall policy (v34.03) effect: read questions: - What does my agentless WAAS app firewall policy look like under v34.03? - Can I read the agentless app firewall rules through v34.03? instructions: - text: Get the agentless app firewall policy with v34.03. - text: Show the v34.03 agentless WAAS rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/agentless'].put update: x-apievangelist-phrasing: intent: Set the agentless app firewall policy (v34.03) effect: write questions: - How do I set the agentless WAAS policy rules via v34.03? - Can I limit the agentless app firewall to a port range on v34.03? instructions: - text: Set the agentless app firewall policy through v34.03. - text: Set the v34.03 agentless firewall port range from {minPort} to {maxPort}. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/agentless/impacted'].get update: x-apievangelist-phrasing: intent: List resources impacted by an agentless WAAS rule (v34.03) effect: read questions: - Which resources does an agentless app firewall rule cover in v34.03? - Can I page through agentless WAAS impacted resources on v34.03? instructions: - text: List resources impacted by agentless firewall rule {rule} via v34.03. slots: rule: query.ruleName - text: Show {limit} resources hit by agentless WAAS rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/agentless/resources'].get update: x-apievangelist-phrasing: intent: List agentless app firewall resources (v34.03) effect: read questions: - What resources are protected by the agentless app firewall under a given config in v34.03? - Can I filter agentless WAAS resources by config ID on v34.03? instructions: - text: List agentless app firewall resources for config {configID} using v34.03. slots: configID: query.configID - text: Show the v34.03 agentless WAAS resource list. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/agentless/state'].get update: x-apievangelist-phrasing: intent: Get agentless app firewall policy state (v34.03) effect: read questions: - Is my agentless app firewall policy deployed and in sync under v34.03? - What state is the agentless WAAS policy in on v34.03? instructions: - text: Get the agentless app firewall policy state via v34.03. - text: Check the v34.03 agentless WAAS deployment state. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/apispec'].post update: x-apievangelist-phrasing: intent: Generate a WAAS API specification object (v34.03) effect: read questions: - Can WAAS generate an API specification object for me in v34.03? - How do I produce a WAAS API spec object via the v34.03 API? instructions: - text: Generate a WAAS API specification object using v34.03. - text: Build a v34.03 WAAS API spec object. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/app-embedded'].get update: x-apievangelist-phrasing: intent: Get the WAAS app-embedded policy (v34.03) effect: read questions: - What WAAS rules protect my app-embedded defenders under v34.03? - Can I read the app-embedded web application firewall policy on v34.03? instructions: - text: Get the WAAS app-embedded policy via v34.03. - text: Show v34.03 app-embedded WAAS rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/app-embedded'].put update: x-apievangelist-phrasing: intent: Update the WAAS app-embedded policy (v34.03) effect: write questions: - How do I update WAAS rules for app-embedded defenders with v34.03? - Can I set the port range of the app-embedded WAAS policy on v34.03? instructions: - text: Update the app-embedded WAAS policy through v34.03. - text: Set app-embedded WAAS ports {minPort} to {maxPort} using v34.03. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/container'].get update: x-apievangelist-phrasing: intent: Get the WAAS container policy (v34.03) effect: read questions: - Which WAAS rules protect my containerized web apps under v34.03? - Can I fetch the container WAAS policy with v34.03? instructions: - text: Get the WAAS container policy via v34.03. - text: Show v34.03 container web app firewall rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/container'].put update: x-apievangelist-phrasing: intent: Update the WAAS container policy (v34.03) effect: write questions: - How do I change WAAS protection for containers through v34.03? - Can I replace the container WAAS rules on v34.03? instructions: - text: Update the container WAAS policy using v34.03. - text: Replace v34.03 container WAAS rules with {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/container/impacted'].get update: x-apievangelist-phrasing: intent: List containers impacted by a WAAS rule (v34.03) effect: read questions: - Which containers are covered by a container app firewall rule in v34.03? - Can I sort containers impacted by a WAAS rule on v34.03? instructions: - text: List containers impacted by WAAS rule {rule} via v34.03. slots: rule: query.ruleName - text: Show {limit} containers under container firewall rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/host'].get update: x-apievangelist-phrasing: intent: Get the WAAS host policy (v34.03) effect: read questions: - What WAAS rules protect web apps running directly on hosts in v34.03? - Can I read the host WAAS policy on v34.03? instructions: - text: Get the WAAS host policy with v34.03. - text: Show v34.03 host web app firewall rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/host'].put update: x-apievangelist-phrasing: intent: Update the WAAS host policy (v34.03) effect: write questions: - How do I update host WAAS rules through v34.03? - Can I change the host app firewall port range on v34.03? instructions: - text: Update the host WAAS policy via v34.03. - text: Set host WAAS ports {minPort} to {maxPort} using v34.03. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/host/impacted'].get update: x-apievangelist-phrasing: intent: List hosts impacted by a WAAS rule (v34.03) effect: read questions: - Which hosts does a host app firewall rule apply to in v34.03? - Can I page through hosts impacted by a WAAS rule on v34.03? instructions: - text: List hosts impacted by WAAS rule {rule} using v34.03. slots: rule: query.ruleName - text: Show {limit} hosts under host firewall rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/network-list'].get update: x-apievangelist-phrasing: intent: List WAAS network lists (v34.03) effect: read questions: - What IP network lists are defined for WAAS in v34.03? - Can I see the subnets in my WAAS network lists via v34.03? instructions: - text: List WAAS network lists using v34.03. - text: Show all v34.03 WAAS network lists and their subnets. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/network-list'].put update: x-apievangelist-phrasing: intent: Update a WAAS network list (v34.03) effect: write questions: - How do I change the subnets in an existing WAAS network list on v34.03? - Can I rename a WAAS network list through v34.03? instructions: - text: Update WAAS network list {name} with subnets {subnets} via v34.03. slots: name: requestBody.name subnets: requestBody.subnets - text: Rename WAAS network list {previousName} to {name} using v34.03. slots: previousName: requestBody.previousName name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/network-list'].post update: x-apievangelist-phrasing: intent: Add a WAAS network list (v34.03) effect: write questions: - How do I create a new IP network list for WAAS with v34.03? - Can I add a WAAS network list of subnets on v34.03? instructions: - text: Add WAAS network list {name} with subnets {subnets} via v34.03. slots: name: requestBody.name subnets: requestBody.subnets - text: Create a new v34.03 WAAS network list named {name}. slots: name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/network-list/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a WAAS network list (v34.03) effect: destructive questions: - How do I remove a WAAS network list using v34.03? - Can I delete a network list that WAAS rules reference on v34.03? instructions: - text: Delete WAAS network list {id} via v34.03. slots: id: path.id - text: Remove network list {id} from WAAS using v34.03. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/out-of-band'].get update: x-apievangelist-phrasing: intent: Get the out-of-band WAAS policy (v34.03) effect: read questions: - What out-of-band WAAS rules inspect mirrored traffic in v34.03? - Can I read the out-of-band web app firewall policy on v34.03? instructions: - text: Get the out-of-band WAAS policy with v34.03. - text: Show v34.03 out-of-band WAAS rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/out-of-band'].put update: x-apievangelist-phrasing: intent: Update the out-of-band WAAS policy (v34.03) effect: write questions: - How do I update out-of-band WAAS rules through v34.03? - Can I set the port range for out-of-band WAAS on v34.03? instructions: - text: Update the out-of-band WAAS policy via v34.03. - text: Set out-of-band WAAS ports {minPort} to {maxPort} on v34.03. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/out-of-band/impacted'].get update: x-apievangelist-phrasing: intent: List resources impacted by an out-of-band WAAS rule (v34.03) effect: read questions: - Which resources does an out-of-band WAAS rule cover in v34.03? - Can I page through out-of-band WAAS impacted resources on v34.03? instructions: - text: List resources impacted by out-of-band rule {rule} using v34.03. slots: rule: query.ruleName - text: Show {limit} resources under out-of-band WAAS rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/serverless'].get update: x-apievangelist-phrasing: intent: Get the WAAS serverless policy (v34.03) effect: read questions: - What WAAS rules protect my serverless functions in v34.03? - Can I fetch the serverless web app firewall policy via v34.03? instructions: - text: Get the WAAS serverless policy with v34.03. - text: Show v34.03 serverless WAAS rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/app/serverless'].put update: x-apievangelist-phrasing: intent: Update the WAAS serverless policy (v34.03) effect: write questions: - How do I change WAAS protection for functions through v34.03? - Can I replace the serverless WAAS rules on v34.03? instructions: - text: Update the serverless WAAS policy via v34.03. - text: Replace v34.03 serverless WAAS rules with {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/network'].get update: x-apievangelist-phrasing: intent: Get the CNNS container and host policy (v34.03) effect: read questions: - What cloud native network segmentation rules apply to containers and hosts in v34.03? - Can I read the CNNS firewall policy on v34.03? instructions: - text: Get the CNNS container and host policy via v34.03. - text: Show v34.03 CNNS network firewall rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/firewall/network'].put update: x-apievangelist-phrasing: intent: Update the CNNS container and host policy (v34.03) effect: write questions: - How do I turn CNNS on for containers but off for hosts with v34.03? - Can I update the CNNS network entities and rules through v34.03? instructions: - text: Update the CNNS policy via v34.03 with container rules {containerRules}. slots: containerRules: requestBody.containerRules - text: Set CNNS host enforcement to {hostEnabled} using v34.03. slots: hostEnabled: requestBody.hostEnabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/app-embedded'].get update: x-apievangelist-phrasing: intent: Get the runtime app-embedded policy (v34.03) effect: read questions: - What runtime defense rules apply to app-embedded defenders in v34.03? - Can I read the app-embedded runtime policy on v34.03? instructions: - text: Get the runtime app-embedded policy with v34.03. - text: Show v34.03 app-embedded runtime rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/app-embedded'].put update: x-apievangelist-phrasing: intent: Replace the runtime app-embedded policy (v34.03) effect: write questions: - How do I replace all app-embedded runtime rules at once with v34.03? - Can I overwrite the full app-embedded runtime rule set on v34.03? instructions: - text: Replace the app-embedded runtime policy via v34.03 with {rules}. slots: rules: requestBody.rules - text: Overwrite all v34.03 app-embedded runtime rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/app-embedded'].post update: x-apievangelist-phrasing: intent: Add an app-embedded runtime rule (v34.03) effect: write questions: - How do I add a single app-embedded runtime rule with v34.03? - Can a new app-embedded runtime rule turn on WildFire analysis in v34.03? instructions: - text: Add app-embedded runtime rule {name} via v34.03. slots: name: requestBody.name - text: Add v34.03 app-embedded runtime rule {name} scoped to collections {collections}. slots: name: requestBody.name collections: requestBody.collections method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/container'].get update: x-apievangelist-phrasing: intent: Get the runtime container policy (v34.03) effect: read questions: - What runtime defense rules protect my containers in v34.03? - Can I fetch the container runtime policy through v34.03? instructions: - text: Get the runtime container policy using v34.03. - text: Show v34.03 container runtime defense rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/container'].put update: x-apievangelist-phrasing: intent: Set the container runtime policy (v34.03) effect: write questions: - How do I replace the whole container runtime rule set with v34.03? - Can I disable runtime learning for containers on v34.03? instructions: - text: Set the container runtime policy via v34.03 with {rules}. slots: rules: requestBody.rules - text: Set container runtime learning disabled to {learningDisabled} using v34.03. slots: learningDisabled: requestBody.learningDisabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/container'].post update: x-apievangelist-phrasing: intent: Add or update a container runtime rule (v34.03) effect: write questions: - How do I add one container runtime rule without replacing the rest in v34.03? - Can a single container runtime rule skip exec sessions on v34.03? instructions: - text: Add container runtime rule {name} via v34.03. slots: name: requestBody.name - text: Update v34.03 container runtime rule {name} with processes {processes}. slots: name: requestBody.name processes: requestBody.processes method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/container/impacted'].get update: x-apievangelist-phrasing: intent: List containers impacted by a runtime rule (v34.03) effect: read questions: - Which containers are affected by a runtime rule in v34.03? - Can I page through containers impacted by runtime rule changes on v34.03? instructions: - text: List containers impacted by runtime rule {rule} using v34.03. slots: rule: query.ruleName - text: Show {limit} containers under runtime rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/host'].get update: x-apievangelist-phrasing: intent: Get the runtime host policy (v34.03) effect: read questions: - What runtime defense rules protect my hosts in v34.03? - Can I read the host runtime policy through v34.03? instructions: - text: Get the runtime host policy with v34.03. - text: Show v34.03 host runtime defense rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/host'].put update: x-apievangelist-phrasing: intent: Set the host runtime policy (v34.03) effect: write questions: - How do I replace every host runtime rule in one call with v34.03? - Can I set the owner of the host runtime policy on v34.03? instructions: - text: Set the host runtime policy via v34.03 with {rules}. slots: rules: requestBody.rules - text: Overwrite all v34.03 host runtime rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/host'].post update: x-apievangelist-phrasing: intent: Add or update a host runtime rule (v34.03) effect: write questions: - How do I add a single host runtime rule with anti-malware settings in v34.03? - Can one host runtime rule define file integrity and log inspection rules on v34.03? instructions: - text: Add host runtime rule {name} via v34.03. slots: name: requestBody.name - text: Update v34.03 host runtime rule {name} with anti-malware {antiMalware}. slots: name: requestBody.name antiMalware: requestBody.antiMalware method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/serverless'].get update: x-apievangelist-phrasing: intent: Get the runtime serverless policy (v34.03) effect: read questions: - What runtime defense rules protect my functions in v34.03? - Can I fetch the serverless runtime policy with v34.03? instructions: - text: Get the runtime serverless policy via v34.03. - text: Show v34.03 serverless runtime defense rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/serverless'].put update: x-apievangelist-phrasing: intent: Set the serverless runtime policy (v34.03) effect: write questions: - Can I swap out every function runtime rule in one call on v34.03? - Can I turn off runtime learning for functions on v34.03? instructions: - text: Set the serverless runtime policy via v34.03 with {rules}. slots: rules: requestBody.rules - text: Set serverless runtime learning disabled to {learningDisabled} using v34.03. slots: learningDisabled: requestBody.learningDisabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/runtime/serverless'].post update: x-apievangelist-phrasing: intent: Add or update a serverless runtime rule (v34.03) effect: write questions: - How do I add one serverless runtime rule without touching the others in v34.03? - Can a single serverless runtime rule enforce DNS restrictions on v34.03? instructions: - text: Add serverless runtime rule {name} via v34.03. slots: name: requestBody.name - text: Update v34.03 serverless runtime rule {name} with DNS settings {dns}. slots: name: requestBody.name dns: requestBody.dns method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/base-images'].get update: x-apievangelist-phrasing: intent: List base image rules (v34.03) effect: read questions: - Which base images are defined so their vulnerabilities are excluded in v34.03? - Can I list my base images rules through v34.03? instructions: - text: List base images rules using v34.03. - text: Show all v34.03 base image rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/base-images'].post update: x-apievangelist-phrasing: intent: Add a base image rule (v34.03) effect: write questions: - How do I register a base image rule with v34.03? - Can I add a description to a new base image rule on v34.03? instructions: - text: Add a base images rule for {images} via v34.03. slots: images: requestBody.images - text: Add v34.03 base image rule {images} described as {description}. slots: images: requestBody.images description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/base-images/download'].get update: x-apievangelist-phrasing: intent: Download base image rules (v34.03) effect: read questions: - Can I export my base images rules as a file with v34.03? - Where do I download base image rules on v34.03? instructions: - text: Download the base images rules via v34.03. - text: Export v34.03 base image rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/base-images/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a base image rule (v34.03) effect: destructive questions: - How do I remove a base image rule using v34.03? - Is deleting a base image rule on v34.03 reversible? instructions: - text: Delete base images rule {id} via v34.03. slots: id: path.id - text: Remove v34.03 base image rule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/ci/images'].get update: x-apievangelist-phrasing: intent: Get the CI image vulnerability policy (v34.03) effect: read questions: - What vulnerability thresholds fail images scanned in CI under v34.03? - Can I read the CI image vulnerability policy on v34.03? instructions: - text: Get the CI image vulnerability policy with v34.03. - text: Show v34.03 vulnerability rules for CI image scans. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/ci/images'].put update: x-apievangelist-phrasing: intent: Update the CI image vulnerability policy (v34.03) effect: write questions: - How do I change the vulnerability rules that gate CI image builds with v34.03? - Can I replace CI image vulnerability rules on v34.03? instructions: - text: Update the CI image vulnerability policy via v34.03. - text: Set v34.03 CI image vulnerability rules to {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/ci/serverless'].get update: x-apievangelist-phrasing: intent: Get the CI serverless vulnerability policy (v34.03) effect: read questions: - Which vulnerability rules apply to functions scanned in CI in v34.03? - Can I fetch the CI serverless vulnerability policy via v34.03? instructions: - text: Get the CI serverless vulnerability policy using v34.03. - text: Show v34.03 vulnerability rules for CI function scans. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/ci/serverless'].put update: x-apievangelist-phrasing: intent: Update the CI serverless vulnerability policy (v34.03) effect: write questions: - How do I update CI serverless vulnerability rules through v34.03? - Can I overwrite vulnerability rules for CI function scans on v34.03? instructions: - text: Update the CI serverless vulnerability policy via v34.03. - text: Set v34.03 CI serverless vulnerability rules to {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/host'].get update: x-apievangelist-phrasing: intent: Get the host vulnerability policy (v34.03) effect: read questions: - What vulnerability rules apply to my hosts in v34.03? - Can I read the host vulnerability policy with v34.03? instructions: - text: Get the host vulnerability policy via v34.03. - text: Show v34.03 host vulnerability rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/host'].put update: x-apievangelist-phrasing: intent: Update the host vulnerability policy (v34.03) effect: write questions: - How do I change host vulnerability rules using v34.03? - Can I replace the host vulnerability rule set on v34.03? instructions: - text: Update the host vulnerability policy via v34.03. - text: Set v34.03 host vulnerability rules to {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/host/impacted'].get update: x-apievangelist-phrasing: intent: List hosts impacted by a vulnerability rule (v34.03) effect: read questions: - Which hosts are affected by a host vulnerability rule in v34.03? - Is there a paged list of hosts exposed by a host vulnerability rule in v34.03? instructions: - text: List hosts impacted by vulnerability rule {rule} using v34.03. slots: rule: query.ruleName - text: Show {limit} hosts under vulnerability rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/images'].get update: x-apievangelist-phrasing: intent: Get the image vulnerability policy (v34.03) effect: read questions: - What vulnerability rules apply to deployed images in v34.03? - Can I read the image vulnerability policy through the v34.03 API? instructions: - text: Get the vulnerability policy for deployed images with v34.03. - text: Show v34.03 deployed-image vulnerability rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/images'].put update: x-apievangelist-phrasing: intent: Update the image vulnerability policy (v34.03) effect: write questions: - How do I change deployed-image vulnerability rules via v34.03? - Can I overwrite the image vulnerability rules on v34.03? instructions: - text: Update vulnerability rules for deployed images via v34.03. - text: Replace deployed-image vulnerability rules with {rules} on v34.03. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/images/impacted'].get update: x-apievangelist-phrasing: intent: List images impacted by a vulnerability rule (v34.03) effect: read questions: - Which images are affected by an image vulnerability rule in v34.03? - Can I sort images impacted by a vulnerability rule on v34.03? instructions: - text: List images impacted by vulnerability rule {rule} using v34.03. slots: rule: query.ruleName - text: Show {limit} images under vulnerability rule {rule} (v34.03). slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/serverless'].get update: x-apievangelist-phrasing: intent: Get the serverless vulnerability policy (v34.03) effect: read questions: - What vulnerability rules apply to deployed functions in v34.03? - Can I fetch the serverless vulnerability policy with v34.03? instructions: - text: Get the serverless vulnerability policy via v34.03. - text: Show v34.03 function vulnerability rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/policies/vulnerability/serverless'].put update: x-apievangelist-phrasing: intent: Update the serverless vulnerability policy (v34.03) effect: write questions: - How do I update serverless vulnerability rules with v34.03? - Can I replace deployed-function vulnerability rules on v34.03? instructions: - text: Update vulnerability rules for deployed functions via v34.03. - text: Replace deployed-function vulnerability rules with {rules} on v34.03. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/ci/images'].get update: x-apievangelist-phrasing: intent: Get the CI image compliance policy (v34.04) effect: read questions: - Which compliance checks does the 34.04 API apply to images built in CI? - Is there a way to view the CI image compliance policy on version 34.04? instructions: - text: Fetch the CI image compliance policy from the 34.04 API. - text: Read the continuous integration image compliance rules on 34.04. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/ci/images'].put update: x-apievangelist-phrasing: intent: Update the CI image compliance policy (v34.04) effect: write questions: - Can I edit which compliance checks block CI image builds on 34.04? - What gets replaced when I update the CI image compliance policy in 34.04? instructions: - text: Change the CI image compliance policy on the 34.04 API. - text: Apply compliance rules {rules} to CI image scans on 34.04. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/ci/serverless'].get update: x-apievangelist-phrasing: intent: Get the CI serverless compliance policy (v34.04) effect: read questions: - What compliance checks does 34.04 run on functions in the CI pipeline? - Is the CI serverless compliance policy readable on version 34.04? instructions: - text: Fetch the CI serverless compliance policy from 34.04. - text: Read compliance rules for CI function scans on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/ci/serverless'].put update: x-apievangelist-phrasing: intent: Update the CI serverless compliance policy (v34.04) effect: write questions: - Can I change CI serverless compliance rules on the 34.04 API? - What does a 34.04 CI serverless compliance update overwrite? instructions: - text: Change the CI serverless compliance policy on 34.04. - text: Apply compliance rules {rules} to CI function scans on 34.04. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/container'].get update: x-apievangelist-phrasing: intent: Get the container compliance policy (v34.04) effect: read questions: - Which compliance checks run against my containers on 34.04? - Is there a 34.04 call to read container compliance rules? instructions: - text: Fetch the container compliance policy from the 34.04 API. - text: Read my container compliance rules on 34.04. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/container'].put update: x-apievangelist-phrasing: intent: Update the container compliance policy (v34.04) effect: write questions: - Can I edit container compliance rules through the 34.04 API? - What happens to existing container compliance rules when I update them on 34.04? instructions: - text: Change the container compliance policy on 34.04. - text: Apply container compliance rules {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/container/impacted'].get update: x-apievangelist-phrasing: intent: List containers impacted by a compliance rule (v34.04) effect: read questions: - Which containers fall under a specific compliance rule on 34.04? - Can I reverse-sort containers impacted by a compliance rule on 34.04? instructions: - text: Find containers affected by compliance rule {rule} on the 34.04 API. slots: rule: query.ruleName - text: Return {limit} containers impacted by compliance rule {rule} on 34.04. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/host'].get update: x-apievangelist-phrasing: intent: Get the host compliance policy (v34.04) effect: read questions: - Which compliance checks apply to my hosts on the 34.04 API? - Is the host compliance policy available to read on 34.04? instructions: - text: Fetch the host compliance policy from 34.04. - text: Read host compliance rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/host'].put update: x-apievangelist-phrasing: intent: Update the host compliance policy (v34.04) effect: write questions: - Can I edit the host compliance rules on 34.04? - What does updating the host compliance policy on 34.04 replace? instructions: - text: Change the host compliance policy on the 34.04 API. - text: Apply host compliance rules {rules} on 34.04. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/serverless'].get update: x-apievangelist-phrasing: intent: Get the serverless compliance policy (v34.04) effect: read questions: - Which compliance checks run on my deployed functions on 34.04? - Is there a 34.04 endpoint for the serverless compliance policy? instructions: - text: Fetch the deployed-function compliance policy from 34.04. - text: Read compliance rules for deployed functions on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/serverless'].put update: x-apievangelist-phrasing: intent: Update the serverless compliance policy (v34.04) effect: write questions: - Can I edit deployed-function compliance rules on the 34.04 API? - What changes when I update the serverless compliance policy on 34.04? instructions: - text: Change compliance policy for deployed functions on 34.04. - text: Apply serverless compliance rules {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/compliance/vms/impacted'].get update: x-apievangelist-phrasing: intent: List VMs impacted by a compliance rule (v34.04) effect: read questions: - Which VMs fall under a given compliance rule on the 34.04 API? - Can I page through compliance-impacted VMs on 34.04? instructions: - text: Find VMs affected by compliance rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} VMs impacted by compliance rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/agentless'].get update: x-apievangelist-phrasing: intent: Get the agentless app firewall policy (v34.04) effect: read questions: - Which agentless WAAS rules are in place on the 34.04 API? - Is the agentless app firewall policy readable on 34.04? instructions: - text: Fetch the agentless app firewall policy from 34.04. - text: Read agentless WAAS rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/agentless'].put update: x-apievangelist-phrasing: intent: Set the agentless app firewall policy (v34.04) effect: write questions: - Can I replace the agentless WAAS rules on 34.04? - What port range can the agentless app firewall be limited to on 34.04? instructions: - text: Change the agentless app firewall policy on the 34.04 API. - text: Limit the agentless firewall to ports {minPort}-{maxPort} on 34.04. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/agentless/impacted'].get update: x-apievangelist-phrasing: intent: List resources impacted by an agentless WAAS rule (v34.04) effect: read questions: - Which resources are covered by a given agentless WAAS rule on 34.04? - Can I sort agentless firewall impacted resources on the 34.04 API? instructions: - text: Find resources affected by agentless WAAS rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} resources impacted by agentless rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/agentless/resources'].get update: x-apievangelist-phrasing: intent: List agentless app firewall resources (v34.04) effect: read questions: - Which resources does the agentless app firewall protect under one config on 34.04? - Is there a 34.04 call to list agentless WAAS resources by config? instructions: - text: Fetch agentless WAAS resources for config {configID} on 34.04. slots: configID: query.configID - text: Read the agentless app firewall resource list on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/agentless/state'].get update: x-apievangelist-phrasing: intent: Get agentless app firewall policy state (v34.04) effect: read questions: - Has my agentless WAAS policy finished deploying on 34.04? - What deployment state is the agentless app firewall in on the 34.04 API? instructions: - text: Check whether the agentless WAAS policy is deployed on 34.04. - text: Read agentless WAAS deployment status on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/apispec'].post update: x-apievangelist-phrasing: intent: Generate a WAAS API specification object (v34.04) effect: read questions: - Is there a 34.04 call that generates a WAAS API specification object? - Can I get WAAS to produce an API spec object on the 34.04 API? instructions: - text: Produce a WAAS API specification object on 34.04. - text: Create a WAAS API spec object with the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/app-embedded'].get update: x-apievangelist-phrasing: intent: Get the WAAS app-embedded policy (v34.04) effect: read questions: - Which WAAS rules cover app-embedded defenders on 34.04? - Is the app-embedded web app firewall policy readable on the 34.04 API? instructions: - text: Fetch the app-embedded WAAS policy from 34.04. - text: Read app-embedded WAAS rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/app-embedded'].put update: x-apievangelist-phrasing: intent: Update the WAAS app-embedded policy (v34.04) effect: write questions: - Can I edit app-embedded WAAS rules on the 34.04 API? - What port range can the app-embedded WAAS policy use on 34.04? instructions: - text: Change the app-embedded WAAS policy on 34.04. - text: Limit app-embedded WAAS to ports {minPort}-{maxPort} on the 34.04 API. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/container'].get update: x-apievangelist-phrasing: intent: Get the WAAS container policy (v34.04) effect: read questions: - Which WAAS rules protect containerized web apps on 34.04? - Is the container web app firewall policy readable on the 34.04 API? instructions: - text: Fetch the container WAAS policy from 34.04. - text: Read container WAAS rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/container'].put update: x-apievangelist-phrasing: intent: Update the WAAS container policy (v34.04) effect: write questions: - Can I change container WAAS protection on the 34.04 API? - What happens to existing container WAAS rules when I update on 34.04? instructions: - text: Change the container WAAS policy on 34.04. - text: Apply container WAAS rules {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/container/impacted'].get update: x-apievangelist-phrasing: intent: List containers impacted by a WAAS rule (v34.04) effect: read questions: - Which containers does a container app firewall rule cover on 34.04? - Can I page through WAAS-impacted containers on the 34.04 API? instructions: - text: Find containers affected by container WAAS rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} containers impacted by WAAS rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/host'].get update: x-apievangelist-phrasing: intent: Get the WAAS host policy (v34.04) effect: read questions: - Which WAAS rules protect host-based web apps on 34.04? - Is the host web app firewall policy readable on the 34.04 API? instructions: - text: Fetch the host WAAS policy from 34.04. - text: Read host WAAS rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/host'].put update: x-apievangelist-phrasing: intent: Update the WAAS host policy (v34.04) effect: write questions: - Can I edit host WAAS rules on the 34.04 API? - What port range can host WAAS be restricted to on 34.04? instructions: - text: Change the host WAAS policy on 34.04. - text: Limit host WAAS to ports {minPort}-{maxPort} on the 34.04 API. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/host/impacted'].get update: x-apievangelist-phrasing: intent: List hosts impacted by a WAAS rule (v34.04) effect: read questions: - Which hosts does a host app firewall rule cover on 34.04? - Can I sort WAAS-impacted hosts on the 34.04 API? instructions: - text: Find hosts affected by host WAAS rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} hosts impacted by WAAS rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/network-list'].get update: x-apievangelist-phrasing: intent: List WAAS network lists (v34.04) effect: read questions: - Which IP network lists exist for WAAS on the 34.04 API? - Is there a 34.04 call to see WAAS network list subnets? instructions: - text: Fetch all WAAS network lists from 34.04. - text: Read WAAS network lists and subnets on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/network-list'].put update: x-apievangelist-phrasing: intent: Update a WAAS network list (v34.04) effect: write questions: - Can I change subnets in an existing WAAS network list on 34.04? - Is renaming a WAAS network list supported on the 34.04 API? instructions: - text: Change WAAS network list {name} to subnets {subnets} on 34.04. slots: name: requestBody.name subnets: requestBody.subnets - text: Rename WAAS network list {previousName} as {name} on the 34.04 API. slots: previousName: requestBody.previousName name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/network-list'].post update: x-apievangelist-phrasing: intent: Add a WAAS network list (v34.04) effect: write questions: - Can I create a new WAAS network list of subnets on 34.04? - What fields does a new WAAS network list take on the 34.04 API? instructions: - text: Create WAAS network list {name} with subnets {subnets} on 34.04. slots: name: requestBody.name subnets: requestBody.subnets - text: Add a new WAAS network list named {name} on the 34.04 API. slots: name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/network-list/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a WAAS network list (v34.04) effect: destructive questions: - Can I delete a WAAS network list on the 34.04 API? - What happens to WAAS rules when their network list is deleted on 34.04? instructions: - text: Delete WAAS network list {id} on 34.04. slots: id: path.id - text: Remove network list {id} from WAAS on the 34.04 API. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/out-of-band'].get update: x-apievangelist-phrasing: intent: Get the out-of-band WAAS policy (v34.04) effect: read questions: - Which out-of-band WAAS rules inspect mirrored traffic on 34.04? - Is the out-of-band web app firewall policy readable on the 34.04 API? instructions: - text: Fetch the out-of-band WAAS policy from 34.04. - text: Read out-of-band WAAS rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/out-of-band'].put update: x-apievangelist-phrasing: intent: Update the out-of-band WAAS policy (v34.04) effect: write questions: - Can I edit out-of-band WAAS rules on the 34.04 API? - What port range can out-of-band WAAS inspect on 34.04? instructions: - text: Change the out-of-band WAAS policy on 34.04. - text: Limit out-of-band WAAS to ports {minPort}-{maxPort} on the 34.04 API. slots: minPort: requestBody.minPort maxPort: requestBody.maxPort method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/out-of-band/impacted'].get update: x-apievangelist-phrasing: intent: List resources impacted by an out-of-band WAAS rule (v34.04) effect: read questions: - Which resources does an out-of-band WAAS rule cover on 34.04? - Can I sort out-of-band impacted resources on the 34.04 API? instructions: - text: Find resources affected by out-of-band rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} resources impacted by out-of-band WAAS rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/serverless'].get update: x-apievangelist-phrasing: intent: Get the WAAS serverless policy (v34.04) effect: read questions: - Which WAAS rules protect my functions on the 34.04 API? - Is the serverless web app firewall policy readable on 34.04? instructions: - text: Fetch the serverless WAAS policy from 34.04. - text: Read serverless WAAS rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/app/serverless'].put update: x-apievangelist-phrasing: intent: Update the WAAS serverless policy (v34.04) effect: write questions: - Can I change WAAS protection for functions on the 34.04 API? - Will updating WAAS for functions on 34.04 drop the function rules I already have? instructions: - text: Change the serverless WAAS policy on 34.04. - text: Apply serverless WAAS rules {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/network'].get update: x-apievangelist-phrasing: intent: Get the CNNS container and host policy (v34.04) effect: read questions: - Which CNNS network segmentation rules apply to containers and hosts on 34.04? - Is the CNNS firewall policy readable on the 34.04 API? instructions: - text: Fetch the CNNS container and host policy from 34.04. - text: Read CNNS network firewall rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/firewall/network'].put update: x-apievangelist-phrasing: intent: Update the CNNS container and host policy (v34.04) effect: write questions: - Can I enable CNNS for hosts but not containers on 34.04? - What network entities can the CNNS policy define on the 34.04 API? instructions: - text: Change the CNNS policy on 34.04 with host rules {hostRules}. slots: hostRules: requestBody.hostRules - text: Turn CNNS container enforcement to {containerEnabled} on the 34.04 API. slots: containerEnabled: requestBody.containerEnabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/app-embedded'].get update: x-apievangelist-phrasing: intent: Get the runtime app-embedded policy (v34.04) effect: read questions: - Which runtime defense rules cover app-embedded defenders on 34.04? - Is the app-embedded runtime policy readable on the 34.04 API? instructions: - text: Fetch the app-embedded runtime policy from 34.04. - text: Read app-embedded runtime rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/app-embedded'].put update: x-apievangelist-phrasing: intent: Replace the runtime app-embedded policy (v34.04) effect: write questions: - Can I swap in a whole new app-embedded runtime rule set on 34.04? - What does replacing the app-embedded runtime policy on 34.04 discard? instructions: - text: Replace the app-embedded runtime policy on 34.04 with {rules}. slots: rules: requestBody.rules - text: Overwrite every app-embedded runtime rule on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/app-embedded'].post update: x-apievangelist-phrasing: intent: Add an app-embedded runtime rule (v34.04) effect: write questions: - Can I add one app-embedded runtime rule on the 34.04 API? - Does a new app-embedded runtime rule support WildFire analysis on 34.04? instructions: - text: Create app-embedded runtime rule {name} on 34.04. slots: name: requestBody.name - text: Create app-embedded runtime rule {name} for collections {collections} on the 34.04 API. slots: name: requestBody.name collections: requestBody.collections method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/container'].get update: x-apievangelist-phrasing: intent: Get the runtime container policy (v34.04) effect: read questions: - Which runtime defense rules protect containers on the 34.04 API? - Is the container runtime policy readable on 34.04? instructions: - text: Fetch the container runtime policy from 34.04. - text: Read container runtime defense rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/container'].put update: x-apievangelist-phrasing: intent: Set the container runtime policy (v34.04) effect: write questions: - Can I replace every container runtime rule at once on 34.04? - Is turning off container runtime learning possible on the 34.04 API? instructions: - text: Replace the container runtime policy on 34.04 with {rules}. slots: rules: requestBody.rules - text: Switch container runtime learning disabled to {learningDisabled} on the 34.04 API. slots: learningDisabled: requestBody.learningDisabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/container'].post update: x-apievangelist-phrasing: intent: Add or update a container runtime rule (v34.04) effect: write questions: - Can I add a single container runtime rule on 34.04 without replacing the rest? - Which effects can one container runtime rule set for Kubernetes enforcement on 34.04? instructions: - text: Create container runtime rule {name} on 34.04. slots: name: requestBody.name - text: Change container runtime rule {name} network settings to {network} on the 34.04 API. slots: name: requestBody.name network: requestBody.network method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/container/impacted'].get update: x-apievangelist-phrasing: intent: List containers impacted by a runtime rule (v34.04) effect: read questions: - Which containers fall under a container runtime rule on 34.04? - Can I sort runtime-impacted containers on the 34.04 API? instructions: - text: Find containers affected by runtime rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} containers impacted by runtime rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/host'].get update: x-apievangelist-phrasing: intent: Get the runtime host policy (v34.04) effect: read questions: - Which runtime defense rules protect hosts on the 34.04 API? - Is the host runtime policy readable on 34.04? instructions: - text: Fetch the host runtime policy from 34.04. - text: Read host runtime defense rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/host'].put update: x-apievangelist-phrasing: intent: Set the host runtime policy (v34.04) effect: write questions: - Can I replace every host runtime rule in one request on 34.04? - What does setting the host runtime policy on the 34.04 API overwrite? instructions: - text: Replace the host runtime policy on 34.04 with {rules}. slots: rules: requestBody.rules - text: Overwrite every host runtime rule on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/host'].post update: x-apievangelist-phrasing: intent: Add or update a host runtime rule (v34.04) effect: write questions: - Can I add a single host runtime rule with forensic settings on 34.04? - Which checks can one host runtime rule include on the 34.04 API? instructions: - text: Create host runtime rule {name} on 34.04. slots: name: requestBody.name - text: Change host runtime rule {name} file integrity rules to {fileIntegrityRules} on the 34.04 API. slots: name: requestBody.name fileIntegrityRules: requestBody.fileIntegrityRules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/serverless'].get update: x-apievangelist-phrasing: intent: Get the runtime serverless policy (v34.04) effect: read questions: - Which runtime defense rules protect functions on the 34.04 API? - Is the serverless runtime policy readable on 34.04? instructions: - text: Fetch the serverless runtime policy from 34.04. - text: Read serverless runtime defense rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/serverless'].put update: x-apievangelist-phrasing: intent: Set the serverless runtime policy (v34.04) effect: write questions: - Can I replace every serverless runtime rule at once on 34.04? - Is disabling serverless runtime learning possible on the 34.04 API? instructions: - text: Replace the serverless runtime policy on 34.04 with {rules}. slots: rules: requestBody.rules - text: Switch serverless runtime learning disabled to {learningDisabled} on the 34.04 API. slots: learningDisabled: requestBody.learningDisabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/runtime/serverless'].post update: x-apievangelist-phrasing: intent: Add or update a serverless runtime rule (v34.04) effect: write questions: - Can I add a single serverless runtime rule on 34.04 without replacing the others? - Which filesystem controls can one serverless runtime rule set on the 34.04 API? instructions: - text: Create serverless runtime rule {name} on 34.04. slots: name: requestBody.name - text: Change serverless runtime rule {name} filesystem settings to {filesystem} on the 34.04 API. slots: name: requestBody.name filesystem: requestBody.filesystem method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/base-images'].get update: x-apievangelist-phrasing: intent: List base image rules (v34.04) effect: read questions: - Which base images are registered as rules on the 34.04 API? - Is there a 34.04 call to read base images rules? instructions: - text: Fetch base images rules from 34.04. - text: Read all base image rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/base-images'].post update: x-apievangelist-phrasing: intent: Add a base image rule (v34.04) effect: write questions: - Can I register a new base image rule on 34.04? - What fields does a base image rule take on the 34.04 API? instructions: - text: Create a base images rule for {images} on 34.04. slots: images: requestBody.images - text: Create base image rule {images} with note {description} on the 34.04 API. slots: images: requestBody.images description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/base-images/download'].get update: x-apievangelist-phrasing: intent: Download base image rules (v34.04) effect: read questions: - Can I download base images rules as a file on 34.04? - Is there a 34.04 export for base image rules? instructions: - text: Fetch a download of the base images rules on 34.04. - text: Save base image rules as an export from the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/base-images/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a base image rule (v34.04) effect: destructive questions: - Can I delete a base image rule on the 34.04 API? - Is removing a base images rule on 34.04 permanent? instructions: - text: Delete base images rule {id} on 34.04. slots: id: path.id - text: Remove base image rule {id} on the 34.04 API. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/ci/images'].get update: x-apievangelist-phrasing: intent: Get the CI image vulnerability policy (v34.04) effect: read questions: - Which vulnerability rules gate CI image builds on 34.04? - Is the CI image vulnerability policy readable on the 34.04 API? instructions: - text: Fetch the CI image vulnerability policy from 34.04. - text: Read vulnerability rules for CI image scans on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/ci/images'].put update: x-apievangelist-phrasing: intent: Update the CI image vulnerability policy (v34.04) effect: write questions: - Can I change the vulnerability thresholds for CI image scans on 34.04? - What gets replaced when I update the CI image vulnerability policy on the 34.04 API? instructions: - text: Change the CI image vulnerability policy on 34.04. - text: Apply CI image vulnerability rules {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/ci/serverless'].get update: x-apievangelist-phrasing: intent: Get the CI serverless vulnerability policy (v34.04) effect: read questions: - Which vulnerability rules apply to CI function scans on 34.04? - Is the CI serverless vulnerability policy readable on the 34.04 API? instructions: - text: Fetch the CI serverless vulnerability policy from 34.04. - text: Read vulnerability rules for CI function scans on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/ci/serverless'].put update: x-apievangelist-phrasing: intent: Update the CI serverless vulnerability policy (v34.04) effect: write questions: - Can I edit CI serverless vulnerability rules on the 34.04 API? - What does updating the CI serverless vulnerability policy on 34.04 overwrite? instructions: - text: Change the CI serverless vulnerability policy on 34.04. - text: Apply CI serverless vulnerability rules {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/host'].get update: x-apievangelist-phrasing: intent: Get the host vulnerability policy (v34.04) effect: read questions: - Which vulnerability rules apply to hosts on the 34.04 API? - Is the host vulnerability policy readable on 34.04? instructions: - text: Fetch the host vulnerability policy from 34.04. - text: Read host vulnerability rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/host'].put update: x-apievangelist-phrasing: intent: Update the host vulnerability policy (v34.04) effect: write questions: - Can I change host vulnerability rules on 34.04? - What happens to existing host vulnerability rules when I update on the 34.04 API? instructions: - text: Change the host vulnerability policy on 34.04. - text: Apply host vulnerability rules {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/host/impacted'].get update: x-apievangelist-phrasing: intent: List hosts impacted by a vulnerability rule (v34.04) effect: read questions: - Which hosts fall under a host vulnerability rule on 34.04? - Can I sort vulnerability-impacted hosts on the 34.04 API? instructions: - text: Find hosts affected by vulnerability rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} hosts impacted by vulnerability rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/images'].get update: x-apievangelist-phrasing: intent: Get the image vulnerability policy (v34.04) effect: read questions: - Which vulnerability rules apply to deployed images on the 34.04 API? - Is the deployed-image vulnerability policy readable on 34.04? instructions: - text: Fetch the deployed-image vulnerability policy from 34.04. - text: Read deployed-image vulnerability rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/images'].put update: x-apievangelist-phrasing: intent: Update the image vulnerability policy (v34.04) effect: write questions: - Can I change deployed-image vulnerability rules on 34.04? - What does an image vulnerability policy update on the 34.04 API replace? instructions: - text: Revise vulnerability rules for deployed images on 34.04. - text: Overwrite deployed-image vulnerability rules with {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/images/impacted'].get update: x-apievangelist-phrasing: intent: List images impacted by a vulnerability rule (v34.04) effect: read questions: - Which images fall under an image vulnerability rule on 34.04? - Can I page through vulnerability-impacted images on the 34.04 API? instructions: - text: Find images affected by vulnerability rule {rule} on 34.04. slots: rule: query.ruleName - text: Return {limit} images impacted by vulnerability rule {rule} on the 34.04 API. slots: limit: query.limit rule: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/serverless'].get update: x-apievangelist-phrasing: intent: Get the serverless vulnerability policy (v34.04) effect: read questions: - Which vulnerability rules apply to deployed functions on the 34.04 API? - Is the serverless vulnerability policy readable on 34.04? instructions: - text: Fetch the deployed-function vulnerability policy from 34.04. - text: Read function vulnerability rules on the 34.04 API. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/policies/vulnerability/serverless'].put update: x-apievangelist-phrasing: intent: Update the serverless vulnerability policy (v34.04) effect: write questions: - Can I change serverless vulnerability rules on 34.04? - Does a 34.04 update to function vulnerability rules discard the ones already set for deployed functions? instructions: - text: Revise vulnerability rules for deployed functions on 34.04. - text: Overwrite deployed-function vulnerability rules with {rules} on the 34.04 API. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/policy/recommendation'].get update: x-apievangelist-phrasing: intent: Get IoT device policy recommendations effect: read questions: - What firewall rules does IoT Security recommend based on how my devices behave? - Can I get microsegmentation recommendations for one specific IoT device? instructions: - text: Get IoT policy recommendations for tenant {customerid}. slots: customerid: query.customerid - text: Get recommended rules for device {deviceid} in tenant {customerid}. slots: deviceid: query.deviceid customerid: query.customerid method: generated generated: '2026-09-26' - target: $.paths['/Policies/SecurityRules'].get update: x-apievangelist-phrasing: intent: List firewall security rules effect: read questions: - Which security rules are configured in my firewall rulebase? - Can I list the security rules for just one virtual system? instructions: - text: List all security rules in the {location} rulebase. slots: location: query.location - text: Show security rules for vsys {vsys}. slots: vsys: query.vsys method: generated generated: '2026-09-26' - target: $.paths['/Policies/SecurityRules'].put update: x-apievangelist-phrasing: intent: Replace an existing security rule effect: write questions: - How do I change an existing firewall security rule on a PAN-OS firewall? - Does updating a security rule require sending the whole rule definition? instructions: - text: Update security rule {name} with the full new definition. slots: name: query.name - text: Replace security rule {name} in vsys {vsys} with {entry}. slots: name: query.name vsys: query.vsys entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Policies/SecurityRules'].post update: x-apievangelist-phrasing: intent: Create a firewall security rule effect: write questions: - Can I add a new rule that allows traffic between two zones? - What do I define when creating a new security policy rule? instructions: - text: Create security rule {name} in the {location} rulebase. slots: name: query.name location: query.location - text: Add a security rule named {name} with definition {entry}. slots: name: query.name entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Policies/SecurityRules'].delete update: x-apievangelist-phrasing: intent: Delete a firewall security rule effect: destructive questions: - Can I remove a security rule from the rulebase by its name? - What happens to traffic when I delete a firewall security rule? instructions: - text: Delete security rule {name}. slots: name: query.name - text: Remove security rule {name} from vsys {vsys}. slots: name: query.name vsys: query.vsys method: generated generated: '2026-09-26' - target: $.paths['/Policies/NATRules'].get update: x-apievangelist-phrasing: intent: List NAT rules effect: read questions: - Which source and destination NAT rules are configured on my firewall? - Can I look up a single NAT rule by name? instructions: - text: List all NAT rules on the firewall. - text: Show NAT rule {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/Policies/NATRules'].put update: x-apievangelist-phrasing: intent: Update a NAT rule effect: write questions: - Can I change the translation settings of an existing NAT rule? - Which NAT rule gets updated when I pass a rule name? instructions: - text: Update NAT rule {name}. slots: name: query.name - text: Change NAT rule {name} to {entry}. slots: name: query.name entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Policies/NATRules'].post update: x-apievangelist-phrasing: intent: Create a NAT rule effect: write questions: - How do I set up a new destination NAT rule on the firewall? - Which translation types can a new NAT rule use? instructions: - text: Create NAT rule {name}. slots: name: query.name - text: Add NAT rule {name} in vsys {vsys} with definition {entry}. slots: name: query.name vsys: query.vsys entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Policies/NATRules'].delete update: x-apievangelist-phrasing: intent: Delete a NAT rule effect: destructive questions: - Can I remove a NAT rule by its name? - What stops being translated after I delete a NAT rule? instructions: - text: Delete NAT rule {name}. slots: name: query.name - text: Remove NAT rule {name} from the {location} config. slots: name: query.name location: query.location method: generated generated: '2026-09-26' - target: $.paths['/Policies/QoSRules'].get update: x-apievangelist-phrasing: intent: List QoS rules effect: read questions: - Which QoS rules prioritize traffic on my firewall? - Can I filter QoS rules to one virtual system? instructions: - text: List all QoS rules. - text: Show QoS rules for vsys {vsys}. slots: vsys: query.vsys method: generated generated: '2026-09-26' - target: $.paths['/Policies/QoSRules'].put update: x-apievangelist-phrasing: intent: Update a QoS rule effect: write questions: - Can I change which QoS class an existing QoS rule assigns? - Is a QoS rule updated by name or by ID? instructions: - text: Update QoS rule {name}. slots: name: query.name - text: Change QoS rule {name} to {entry}. slots: name: query.name entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Policies/QoSRules'].post update: x-apievangelist-phrasing: intent: Create a QoS rule effect: write questions: - How do I prioritize bandwidth for a critical application with a new QoS rule? - What does a new QoS rule classify traffic into? instructions: - text: Create QoS rule {name}. slots: name: query.name - text: Add QoS rule {name} with definition {entry}. slots: name: query.name entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Policies/QoSRules'].delete update: x-apievangelist-phrasing: intent: Delete a QoS rule effect: destructive questions: - Can I remove a QoS rule I no longer need? - What happens to traffic prioritization when a QoS rule is deleted? instructions: - text: Delete QoS rule {name}. slots: name: query.name - text: Remove QoS rule {name} from vsys {vsys}. slots: name: query.name vsys: query.vsys method: generated generated: '2026-09-26' - target: $.paths['/v1/policies'].get update: x-apievangelist-phrasing: intent: List browser security policies effect: read questions: - Which browser security policies are configured for my tenant? - Can I list only the enabled browser policies? instructions: - text: List browser security policies. - text: Show browser policies where enabled is {enabled}, up to {limit}. slots: enabled: query.enabled limit: query.limit method: generated generated: '2026-09-26' - target: $.paths['/v1/policies'].post update: x-apievangelist-phrasing: intent: Create a browser security policy effect: write questions: - How do I create a Prisma Access Browser policy with web filtering and DLP? - Can a new browser policy control downloads and extensions? instructions: - text: Create browser security policy {name}. slots: name: requestBody.name - text: Create browser policy {name} with DLP enabled set to {dlp_enabled}. slots: name: requestBody.name dlp_enabled: requestBody.dlp_enabled method: generated generated: '2026-09-26' - target: $.paths['/v1/policies/{policy_id}'].get update: x-apievangelist-phrasing: intent: Get a browser security policy effect: read questions: - What settings does a specific browser security policy have? - Can I see the full details of one browser policy? instructions: - text: Get browser security policy {policy_id}. slots: policy_id: path.policy_id - text: Show the full configuration of browser policy {policy_id}. slots: policy_id: path.policy_id method: generated generated: '2026-09-26' - target: $.paths['/v1/policies/{policy_id}'].put update: x-apievangelist-phrasing: intent: Update a browser security policy effect: write questions: - Can I change the download controls on an existing browser policy? - What do I need to send to update a browser security policy? instructions: - text: Update browser policy {policy_id} with name {name}. slots: policy_id: path.policy_id name: requestBody.name - text: Set browser policy {policy_id} ({name}) enabled to {enabled}. slots: policy_id: path.policy_id name: requestBody.name enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/v1/policies/{policy_id}'].delete update: x-apievangelist-phrasing: intent: Delete a browser security policy effect: destructive questions: - Can I delete a browser policy that is still assigned to a deployment? - What must I do before removing a browser security policy? instructions: - text: Delete browser security policy {policy_id}. slots: policy_id: path.policy_id - text: Remove browser policy {policy_id}. slots: policy_id: path.policy_id method: generated generated: '2026-09-26' - target: $.paths['/policies/vulnerability/images'].get update: x-apievangelist-phrasing: intent: Get the image vulnerability policy (unversioned) effect: read questions: - What block, alert and ignore rules apply to container image vulnerabilities on the unversioned endpoint? - Can I read image vulnerability rules by severity and CVE without a version in the path? instructions: - text: Get the image vulnerability policy from the unversioned endpoint. - text: Show image vulnerability block and alert rules without an API version. method: generated generated: '2026-09-26' - target: $.paths['/policies/vulnerability/images'].put update: x-apievangelist-phrasing: intent: Replace the image vulnerability policy (unversioned) effect: write questions: - Can I replace the image vulnerability policy enforced at container admission? - Does replacing the image vulnerability policy on the unversioned endpoint affect all image scans? instructions: - text: Replace the image vulnerability policy on the unversioned endpoint. - text: Replace the unversioned image vulnerability policy with rules {rules}. slots: rules: requestBody.rules method: generated generated: '2026-09-26' - target: $.paths['/policies/compliance/images'].get update: x-apievangelist-phrasing: intent: Get the image compliance policy effect: read questions: - Which CIS benchmark checks are applied to my container images? - Can I see the image compliance policy and its custom rules? instructions: - text: Get the image compliance policy. - text: Show CIS benchmark and custom compliance rules for container images. method: generated generated: '2026-09-26' - target: $.paths['/policies/runtime/container'].get update: x-apievangelist-phrasing: intent: Get the container runtime policy (unversioned) effect: read questions: - What process, network and file system activity is allowed for running containers on the unversioned endpoint? - Can I read the container runtime defense policy without a version in the path? instructions: - text: Get the container runtime defense policy from the unversioned endpoint. - text: Show allowed container runtime activities without an API version. method: generated generated: '2026-09-26' - target: $.paths['/policy'].get update: x-apievangelist-phrasing: intent: List policies (v1) effect: read questions: - Which high-severity policies are enabled in Prisma Cloud? - Can I list policies mapped to a particular compliance standard with the original endpoint? instructions: - text: List every policy from the original v1 policy endpoint, built-in and custom. - text: Using the original policy list, show each policy's severity, cloud type and compliance mappings. method: generated generated: '2026-10-01' - target: $.paths['/policy'].post update: x-apievangelist-phrasing: intent: Create a custom policy effect: write questions: - How do I create my own custom policy with a rule and severity? - Can I attach a remediation recommendation and cloud type to a new custom policy? instructions: - text: Create a {policyType} policy named {name} with severity {severity} and rule {rule}. slots: policyType: requestBody.policyType name: requestBody.name severity: requestBody.severity rule: requestBody.rule - text: Add custom policy {name} for cloud type {cloudType} with recommendation {recommendation}. slots: name: requestBody.name cloudType: requestBody.cloudType recommendation: requestBody.recommendation method: generated generated: '2026-10-01' - target: $.paths['/policy/{policyId}'].get update: x-apievangelist-phrasing: intent: Get cloud security policy details effect: read questions: - What does a specific RQL cloud security policy check for? - Can I look up one cloud policy's details by its ID? instructions: - text: Get cloud security policy {policyId}. slots: policyId: path.policyId - text: Show details of RQL policy {policyId}. slots: policyId: path.policyId method: generated generated: '2026-09-26' - target: $.paths['/policy/{policyId}'].put update: x-apievangelist-phrasing: intent: Update a cloud security policy effect: write questions: - Can I change the severity or RQL rule of an existing cloud security policy? - Which fields must I resend when updating a cloud policy? instructions: - text: Update cloud policy {policyId} to severity {severity}. slots: policyId: path.policyId severity: requestBody.severity - text: Update RQL policy {policyId} named {name} of type {policyType} with rule {rule}. slots: policyId: path.policyId name: requestBody.name policyType: requestBody.policyType rule: requestBody.rule method: generated generated: '2026-09-26' - target: $.paths['/dspm/api/v1/policies'].get update: x-apievangelist-phrasing: intent: List data security (DSPM) policies effect: read questions: - Which data security policies require encryption for sensitive data? - Can I search DSPM policies by name and show only enabled ones? instructions: - text: List DSPM policies. - text: Search DSPM policies for {search} where enabled is {enabled}. slots: search: query.search enabled: query.enabled method: generated generated: '2026-09-26'