# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview User Roles API version: 1.0.0 extends: openapi/palo-alto-networks-user-roles-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 7 - target: $.paths['/user/role'].get update: x-apievangelist-phrasing: intent: List Prisma Cloud user roles effect: read questions: - Which user roles exist in my Prisma Cloud tenant with their full settings? - What account groups does each user role grant access to? instructions: - text: List all user roles with their details. - text: Show every role and the account groups it can access. method: generated generated: '2026-09-26' - target: $.paths['/user/role'].post update: x-apievangelist-phrasing: intent: Create a user role effect: write questions: - How do I create a custom role that only sees certain account groups? - Can a new role be limited to specific code repositories or resource lists? - Can I stop a role from dismissing alerts? instructions: - text: Create user role {name} of type {roleType} for account groups {accountGroupIds}. slots: name: requestBody.name roleType: requestBody.roleType accountGroupIds: requestBody.accountGroupIds - text: Add a {roleType} role named {name} with access to repositories {codeRepositoryIds}. slots: name: requestBody.name roleType: requestBody.roleType codeRepositoryIds: requestBody.codeRepositoryIds method: generated generated: '2026-09-26' - target: $.paths['/user/role/name'].get update: x-apievangelist-phrasing: intent: List user role IDs and names effect: read questions: - What are just the names and IDs of my user roles? - Where do I find a role's ID when I only know its name? instructions: - text: List user role names and IDs. - text: Give me a lookup of role names to IDs. method: generated generated: '2026-09-26' - target: $.paths['/user/role/type'].get update: x-apievangelist-phrasing: intent: List permission groups for user roles effect: read questions: - Which permission groups can a user role be based on? - What role types are available besides the default ones? instructions: - text: List the available user role types. - text: Show the permission groups I can pick when creating a role. method: generated generated: '2026-09-26' - target: $.paths['/user/role/{id}'].get update: x-apievangelist-phrasing: intent: Get a user role effect: read questions: - Where do I see the settings of one specific user role? - Which users are associated with a particular role? instructions: - text: Get user role {id}. slots: id: path.id - text: Show the account groups and associated users of role {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/user/role/{id}'].put update: x-apievangelist-phrasing: intent: Update a user role effect: write questions: - How do I change which account groups an existing role can access? - Can I rename an existing user role? instructions: - text: Update role {id} to name {name} and type {roleType}. slots: id: path.id name: requestBody.name roleType: requestBody.roleType - text: Give existing role {id} access to resource lists {resourceListIds}. slots: id: path.id resourceListIds: requestBody.resourceListIds method: generated generated: '2026-09-26' - target: $.paths['/user/role/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a user role effect: destructive questions: - Can I remove a role I no longer need? - What happens to associated application users when their role is deleted? instructions: - text: Delete user role {id}. slots: id: path.id - text: Remove the role with ID {id}. slots: id: path.id method: generated generated: '2026-09-26'