# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Security Services Security Rules API version: 1.0.0 extends: openapi/palo-alto-networks-security-rules-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 17 - target: $.paths['/security-rules'].get update: x-apievangelist-phrasing: intent: List security rules effect: read questions: - Which security rules are in my pre-rulebase for a folder? - Can I find a security rule by name in Strata Cloud Manager? instructions: - text: List {position} security rules in folder {folder}. slots: position: query.position folder: query.folder - text: Find the {position} security rule named {name}. slots: position: query.position name: query.name method: generated generated: '2026-09-26' - target: $.paths['/security-rules'].post update: x-apievangelist-phrasing: intent: Create a Prisma Access security rule effect: write questions: - How do I add a security rule to the Prisma Access candidate configuration? - Does a new Prisma Access rule take effect immediately or only after a push? instructions: - text: Create a Prisma Access candidate-config security rule in the {position} rulebase. slots: position: query.position - text: Add a new Prisma Access policy rule to the {position} rules of the candidate configuration. slots: position: query.position method: generated generated: '2026-10-01' - target: $.paths['/security-rules/{id}'].get update: x-apievangelist-phrasing: intent: Get a security rule effect: read questions: - What sources, destinations and actions does one security rule have? - Can I retrieve a single security rule by id? instructions: - text: Show security rule {id}. slots: id: path.id - text: Get the full definition of security rule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/security-rules/{id}'].put update: x-apievangelist-phrasing: intent: Update a Prisma Access security rule effect: write questions: - How do I edit a Prisma Access security rule in the candidate configuration? - Can I change an existing Prisma Access rule without pushing the config right away? instructions: - text: Update Prisma Access rule {id} in the candidate config. slots: id: path.id - text: Save my edits to Prisma Access candidate-config security rule {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/security-rules/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a security rule effect: destructive questions: - How do I delete a security rule from the policy? - Can I remove an obsolete security rule by its id? instructions: - text: Delete security rule {id}. slots: id: path.id - text: Remove the obsolete security rule {id} from policy. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/security-rules/{id}:move'].post update: x-apievangelist-phrasing: intent: Reorder a security rule in the rulebase effect: write questions: - How do I move a security rule to the top of the rulebase? - Can I place one security rule right before another rule? instructions: - text: Move security rule {id} to {destination} of the {rulebase} rulebase. slots: id: path.id destination: requestBody.destination rulebase: requestBody.rulebase - text: Move security rule {id} {destination} rule {destination_rule} in the {rulebase} rulebase. slots: id: path.id destination: requestBody.destination destination_rule: requestBody.destination_rule rulebase: requestBody.rulebase method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/security-rules'].get update: x-apievangelist-phrasing: intent: List security rules via the SSE config API effect: read questions: - Which security rules are in the pre or post rulebase of a folder through the SSE config v1 endpoint? - Can I look up an SSE security rule by name within a folder? instructions: - text: List the {position} SSE security rules in folder {folder}. slots: position: query.position folder: query.folder - text: Find the SSE config security rule named {name} in folder {folder} at position {position}. slots: name: query.name folder: query.folder position: query.position method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/security-rules'].post update: x-apievangelist-phrasing: intent: Create a security rule via the SSE config API effect: write questions: - How do I add a security rule to a folder through the SSE config v1 API? - Can I choose whether a new SSE config rule lands in the pre or post rulebase? instructions: - text: Create an SSE config security rule in folder {folder} at position {position}. slots: folder: query.folder position: query.position - text: Add a new SSE v1 security rule to the {position} rulebase of folder {folder}. slots: position: query.position folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/security-rules/{id}'].get update: x-apievangelist-phrasing: intent: Get a security rule via the SSE config API effect: read questions: - What does one SSE config security rule look like in full? - Can I fetch an SSE security rule by its ID? instructions: - text: Show SSE config security rule {id}. slots: id: path.id - text: Fetch the SSE rule {id} and list its source and destination. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/security-rules/{id}'].put update: x-apievangelist-phrasing: intent: Edit a security rule via the SSE config API effect: write questions: - How do I modify an existing security rule through the SSE config v1 endpoint? - Can I edit an SSE config security rule in place by its ID? instructions: - text: Edit SSE config security rule {id}. slots: id: path.id - text: Apply my changes to SSE v1 security rule {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/security-rules/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a security rule via the SSE config API effect: destructive questions: - How do I remove a security rule using the SSE config v1 endpoint? - Is deleting an SSE config rule by ID permanent? instructions: - text: Delete SSE config security rule {id}. slots: id: path.id - text: Remove the SSE security rule {id} from its rulebase. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/security-rules/{id}:move'].post update: x-apievangelist-phrasing: intent: Reorder a security rule in the rulebase effect: write questions: - How do I move a security rule above or below another rule? - Can I move a rule to the top or bottom of the pre or post rulebase? instructions: - text: Move security rule {id} in folder {folder} to {destination} of the {rulebase} rulebase. slots: id: path.id folder: query.folder destination: requestBody.destination rulebase: requestBody.rulebase - text: Place rule {id} {destination} rule {destination_rule} in the {rulebase} rulebase of folder {folder}. slots: id: path.id destination: requestBody.destination destination_rule: requestBody.destination_rule rulebase: requestBody.rulebase folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/config/rulestacks/{rulestack}/security-rules'].get update: x-apievangelist-phrasing: intent: List Cloud NGFW rulestack security rules effect: read questions: - Which security rules are in a Cloud NGFW rulestack, in priority order? - Can I page through a large rulestack's rules with a next token? instructions: - text: List the security rules in Cloud NGFW rulestack {rulestack}. slots: rulestack: path.rulestack - text: Show the next page of rules in rulestack {rulestack} using token {nexttoken}. slots: rulestack: path.rulestack nexttoken: query.nexttoken method: generated generated: '2026-10-01' - target: $.paths['/config/rulestacks/{rulestack}/security-rules'].post update: x-apievangelist-phrasing: intent: Add a security rule to a Cloud NGFW rulestack effect: write questions: - How do I add a new rule to a Cloud NGFW rulestack at a given priority? - Do lower priority numbers get evaluated first in a Cloud NGFW rulestack? instructions: - text: Add rule {RuleEntry} to Cloud NGFW rulestack {rulestack} at priority {Priority}. slots: rulestack: path.rulestack Priority: requestBody.Priority RuleEntry: requestBody.RuleEntry - text: Insert a new rulestack rule at priority {Priority} in {rulestack} defined as {RuleEntry}. slots: rulestack: path.rulestack Priority: requestBody.Priority RuleEntry: requestBody.RuleEntry method: generated generated: '2026-10-01' - target: $.paths['/config/rulestacks/{rulestack}/security-rules/{priority}'].get update: x-apievangelist-phrasing: intent: Get a Cloud NGFW rule by priority effect: read questions: - What rule sits at a particular priority in my Cloud NGFW rulestack? - Can I see the candidate version of a rulestack rule instead of the running one? instructions: - text: Show the rule at priority {priority} in Cloud NGFW rulestack {rulestack}. slots: rulestack: path.rulestack priority: path.priority - text: Fetch the candidate rule at priority {priority} of rulestack {rulestack}. slots: rulestack: path.rulestack priority: path.priority method: generated generated: '2026-10-01' - target: $.paths['/config/rulestacks/{rulestack}/security-rules/{priority}'].put update: x-apievangelist-phrasing: intent: Update a Cloud NGFW rulestack rule effect: write questions: - How do I change the rule at a given priority in a Cloud NGFW rulestack? - Can I edit a rulestack rule's source, destination or action in place? instructions: - text: Replace the rule at priority {priority} in Cloud NGFW rulestack {rulestack} with {RuleEntry}. slots: rulestack: path.rulestack priority: path.priority RuleEntry: requestBody.RuleEntry - text: Update rulestack {rulestack} rule {priority} to priority {Priority} using entry {RuleEntry}. slots: rulestack: path.rulestack priority: path.priority Priority: requestBody.Priority RuleEntry: requestBody.RuleEntry method: generated generated: '2026-10-01' - target: $.paths['/config/rulestacks/{rulestack}/security-rules/{priority}'].delete update: x-apievangelist-phrasing: intent: Delete a Cloud NGFW rulestack rule effect: destructive questions: - How do I remove a rule from a Cloud NGFW rulestack? - Does deleting the rule at one priority remove it from the rulestack entirely? instructions: - text: Delete the rule at priority {priority} from Cloud NGFW rulestack {rulestack}. slots: rulestack: path.rulestack priority: path.priority - text: Remove rulestack {rulestack}'s priority {priority} rule. slots: rulestack: path.rulestack priority: path.priority method: generated generated: '2026-10-01'