# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview User Profile API version: 1.0.0 extends: openapi/palo-alto-networks-user-profile-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/user/me'].get update: x-apievangelist-phrasing: intent: View my own user profile effect: read questions: - What does my own Prisma Cloud profile say about me, like my roles and time zone? - Where can I check the personal details on the account I'm signed in with? instructions: - text: Show me my own user profile. - text: Look up the profile of the account I'm logged in as. method: generated generated: '2026-09-26' - target: $.paths['/user/me'].put update: x-apievangelist-phrasing: intent: Update my own user profile effect: write questions: - Can I change my own name or time zone without an admin? - How do I switch my default role on my own profile? instructions: - text: Change my own profile's time zone to {timeZone}. slots: timeZone: requestBody.timeZone - text: Update my name on my profile to {firstName} {lastName}. slots: firstName: requestBody.firstName lastName: requestBody.lastName - text: Set my own default role to {defaultRoleId}. slots: defaultRoleId: requestBody.defaultRoleId method: generated generated: '2026-09-26' - target: $.paths['/v3/user'].get update: x-apievangelist-phrasing: intent: List users and service accounts effect: read questions: - Which users and service accounts exist in my tenant? - Can I see service accounts alongside human users in one list? instructions: - text: List every user and service account in my tenant. - text: Show all service accounts and users using the v3 user list. method: generated generated: '2026-09-26' - target: $.paths['/v3/user'].post update: x-apievangelist-phrasing: intent: Add a user or service account effect: write questions: - How do I create a service account for automation instead of a person? - Can I give a new account an access key expiration when I add it? instructions: - text: Add a service account named {username} with role {defaultRoleId}. slots: username: requestBody.username defaultRoleId: requestBody.defaultRoleId - text: Create a user account of type {type} for {email}. slots: type: requestBody.type email: requestBody.email method: generated generated: '2026-09-26' - target: $.paths['/v2/user'].get update: x-apievangelist-phrasing: intent: List users with their roles (v2) effect: read questions: - Which users belong to my tenant and what roles does each hold? - Is there an older list of users that shows multiple roles per person? instructions: - text: List all tenant users with their assigned roles using the v2 endpoint. - text: Show every user and their multiple roles from the v2 user list. method: generated generated: '2026-09-26' - target: $.paths['/v2/user'].post update: x-apievangelist-phrasing: intent: Add an administrative user (v2) effect: write questions: - How do I add a new admin who needs more than one role? - What's required to create an administrative user through the v2 endpoint? instructions: - text: Add admin {email} named {firstName} {lastName} with roles {roleIds} via v2. slots: email: requestBody.email firstName: requestBody.firstName lastName: requestBody.lastName roleIds: requestBody.roleIds - text: Create a v2 administrative user {email} in time zone {timeZone}. slots: email: requestBody.email timeZone: requestBody.timeZone method: generated generated: '2026-09-26' - target: $.paths['/v2/user/{id}'].get update: x-apievangelist-phrasing: intent: Get a user's profile by email effect: read questions: - What roles and settings does a specific user have? - Can I look up one admin's profile by their email? instructions: - text: Get the user profile for {email}. slots: email: path.id - text: Show the roles assigned to user {email}. slots: email: path.id method: generated generated: '2026-09-26' - target: $.paths['/v2/user/{id}'].put update: x-apievangelist-phrasing: intent: Update another user's profile (v2) effect: write questions: - Can I change another admin's roles or time zone? - How do I rename a user in the tenant? instructions: - text: Update user {email}'s roles to {roleIds}. slots: email: path.id roleIds: requestBody.roleIds - text: Change the time zone of user {email} to {timeZone}. slots: email: path.id timeZone: requestBody.timeZone method: generated generated: '2026-09-26' - target: $.paths['/user/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a user or service account effect: destructive questions: - How do I permanently remove someone's account from the tenant? - Can I delete a service account I no longer use? instructions: - text: Delete user profile {id}. slots: id: path.id - text: Remove the service account {id} from my tenant. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/user/{id}/status/{enabled}'].patch update: x-apievangelist-phrasing: intent: Enable or disable a user effect: write questions: - Can I lock a user out temporarily without deleting them? - How do I re-enable an account that was disabled? instructions: - text: Disable user {id} by setting status {enabled}. slots: id: path.id enabled: path.enabled - text: Set the enabled status of user {id} to {enabled}. slots: id: path.id enabled: path.enabled method: generated generated: '2026-09-26' - target: $.paths['/user/name'].get update: x-apievangelist-phrasing: intent: List all user emails effect: read questions: - What email addresses do my active users sign in with? - Is there a quick list of just the emails of non-deleted users? instructions: - text: List the emails of all active users. - text: Give me every user email in the system. method: generated generated: '2026-09-26' - target: $.paths['/user/domain'].get update: x-apievangelist-phrasing: intent: List allowed email domains effect: read questions: - Which email domains are on the allow list for new users? - What domains can user accounts be created under? instructions: - text: List the allow-listed email domains. - text: Show which email domains my tenant permits. method: generated generated: '2026-09-26' - target: $.paths['/user/saml/bypass'].get update: x-apievangelist-phrasing: intent: List users allowed to bypass SSO effect: read questions: - Who can still sign in with a password even though SSO is on? - Which users are allowed to log in through both SAML and username and password? instructions: - text: List the users who can bypass SSO. - text: Show me the SSO bypass allow list. method: generated generated: '2026-09-26' - target: $.paths['/user/saml/bypass'].put update: x-apievangelist-phrasing: intent: Set which users can bypass SSO effect: write questions: - How do I let a break-glass admin log in with a password when SAML is enforced? - Can I change the list of people allowed to skip single sign-on? instructions: - text: Replace the SSO bypass list so the given emails can log in with SAML or a password. - text: Update the users allowed to bypass single sign-on. method: generated generated: '2026-09-26'