# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for TLS Protect Cloud API for Strata Cloud Manager Workload… version: 1.0.0 extends: openapi/palo-alto-networks-workload-issuance-policies-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 5 - target: $.paths['/v1/distributedissuers/policies'].get update: x-apievangelist-phrasing: intent: List Workload Issuance policies effect: read questions: - Which Workload Issuance policies constrain how certificates are issued? - What certificate issuance policies are available to my issuers? instructions: - text: List all Workload Issuance policies. - text: Show every certificate issuance policy with its rules. method: generated generated: '2026-09-26' - target: $.paths['/v1/distributedissuers/policies'].post update: x-apievangelist-phrasing: intent: Create a Workload Issuance policy effect: write questions: - How do I create a policy that restricts which certificates an issuer can create? - Can I share a new Workload Issuance policy with sub-tenants? instructions: - text: Create issuance policy {name} with key algorithm {keyAlgorithm} and validity period {validityPeriod}. slots: name: requestBody.name keyAlgorithm: requestBody.keyAlgorithm validityPeriod: requestBody.validityPeriod - text: Add Workload Issuance policy {name} allowing SANs {sans} and subject {subject}, shared with sub-tenants {sharedWithSubTsgIds}. slots: name: requestBody.name sans: requestBody.sans subject: requestBody.subject sharedWithSubTsgIds: requestBody.sharedWithSubTsgIds method: generated generated: '2026-09-26' - target: $.paths['/v1/distributedissuers/policies/{id}'].get update: x-apievangelist-phrasing: intent: Get a Workload Issuance policy effect: read questions: - What key algorithm and validity period does one issuance policy enforce? - Can I fetch a single Workload Issuance policy by id? instructions: - text: Show Workload Issuance policy {id}. slots: id: path.id - text: Get the rules defined in issuance policy {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/distributedissuers/policies/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a Workload Issuance policy effect: destructive questions: - How do I remove a Workload Issuance policy? - Can I delete a certificate issuance policy that is no longer needed? instructions: - text: Delete Workload Issuance policy {id}. slots: id: path.id - text: Remove issuance policy {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/distributedissuers/policies/{id}'].patch update: x-apievangelist-phrasing: intent: Update a Workload Issuance policy effect: write questions: - How do I change the validity period on an existing issuance policy? - Can I update only some fields of a Workload Issuance policy and leave the rest? instructions: - text: Change the validity period of issuance policy {id} to {validityPeriod}. slots: id: path.id validityPeriod: requestBody.validityPeriod - text: Set shareWithAll to {shareWithAll} on existing issuance policy {id}. slots: shareWithAll: requestBody.shareWithAll id: path.id method: generated generated: '2026-09-26'