vocabulary: "1.0.0" info: provider: Palo Alto Networks description: >- Vocabulary and taxonomy for the Palo Alto Networks API ecosystem, capturing the operational dimension (51 APIs across network security, cloud security, SASE, security operations, and AI security) and capability dimension (10 workflow capabilities composing 41 shared API definitions) to provide a unified view of what this platform offers and how it can be used. created: "2026-04-17" modified: "2026-04-17" # ============================================================ # OPERATIONAL DIMENSION (from OpenAPI) # What the platform exposes at the protocol level # ============================================================ operational: apis: # Network Security - name: PAN-OS REST API namespace: pan-os-rest-api version: v10.2 baseUrl: https://{firewall}/restapi/v10.2 platform: Strata status: active - name: PAN-OS XML API namespace: pan-os-xml-api version: v10.2 baseUrl: https://{firewall}/api/ platform: Strata status: active - name: PAN-OS OpenConfig API namespace: openconfig-api version: "2.0" baseUrl: https://{firewall} platform: Strata status: active - name: Panorama API namespace: panorama-api version: v10.2 baseUrl: https://{panorama}/api/ platform: Strata status: active - name: Strata Cloud Manager API namespace: strata-cloud-manager-api version: v1 baseUrl: https://api.strata.paloaltonetworks.com platform: Strata status: active - name: Cloud NGFW API namespace: cloud-ngfw-api version: v1 baseUrl: https://api.{region}.aws.cloudngfw.paloaltonetworks.com platform: Strata status: active # Cloud-Delivered Security Services - name: WildFire API namespace: wildfire-api version: v1 baseUrl: https://wildfire.paloaltonetworks.com/publicapi/ platform: Cloud Security Services status: active - name: Threat Vault API namespace: threat-vault-api version: v1 baseUrl: https://api.threatvault.paloaltonetworks.com platform: Cloud Security Services status: active - name: AutoFocus API namespace: autofocus-api version: v1.0 baseUrl: https://autofocus.paloaltonetworks.com/api/v1.0/ platform: Cloud Security Services status: deprecated - name: IoT Security API namespace: iot-security-api version: v4.0 baseUrl: https://{customer}.iot.paloaltonetworks.com/pub/v4.0/ platform: Cloud Security Services status: active - name: Data Loss Prevention API namespace: dlp-api version: v2 baseUrl: https://api.dlp.paloaltonetworks.com platform: Cloud Security Services status: active - name: DNS Security API namespace: dns-security-api version: v1 baseUrl: https://api.dns.service.paloaltonetworks.com platform: Cloud Security Services status: active - name: Email DLP API namespace: email-dlp-api version: v1 baseUrl: https://api.dlp.paloaltonetworks.com platform: Cloud Security Services status: active - name: AIOps for NGFW BPA API namespace: aiops-ngfw-bpa-api version: v1 baseUrl: https://api.stratacloud.paloaltonetworks.com platform: Cloud Security Services status: active # SASE - name: Prisma Access API namespace: prisma-access-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: Autonomous DEM API namespace: autonomous-dem-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: Prisma SD-WAN API namespace: prisma-sd-wan-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: ZTNA Connector API namespace: ztna-connector-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: Prisma Access Browser API namespace: prisma-access-browser-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: Configuration Orchestration API namespace: sase-config-orchestration-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: Prisma Access Insights API namespace: prisma-access-insights-api version: v3.0 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE 5G Manage Services API namespace: sase-5g-manage-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE 5G Monitor Services API namespace: sase-5g-monitor-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active # SASE Management Services - name: SASE Tenancy Service API namespace: sase-tenancy-service-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE IAM API namespace: sase-iam-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE Subscription Service API namespace: sase-subscription-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE Authentication Service API namespace: sase-authentication-service-api version: v1 baseUrl: https://auth.apps.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE Aggregate Monitoring API namespace: sase-aggregate-monitoring-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: Strata Logging Service API namespace: strata-logging-service-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SaaS Security API namespace: saas-security-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SaaS Security Posture Management API namespace: sspm-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: Identity Security Posture Management API namespace: identity-security-posture-management-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE Multitenant Notifications API namespace: sase-multitenant-notifications-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active - name: SASE Multitenant Interconnect API namespace: sase-multitenant-interconnect-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com platform: Prisma SASE status: active # Prisma Cloud - name: Prisma Cloud CSPM API namespace: prisma-cloud-cspm-api version: v1 baseUrl: https://api.prismacloud.io platform: Prisma Cloud status: active - name: Prisma Cloud Compute API namespace: prisma-cloud-compute-api version: v1 baseUrl: https://{console}/api/v1 platform: Prisma Cloud status: active - name: Prisma Cloud Code Security API namespace: prisma-cloud-code-security-api version: v1 baseUrl: https://api.prismacloud.io platform: Prisma Cloud status: active - name: Prisma Cloud DSPM API namespace: prisma-cloud-dspm-api version: v1 baseUrl: https://api.prismacloud.io platform: Prisma Cloud status: active - name: Prisma Cloud MSSP API namespace: prisma-cloud-mssp-api version: v1 baseUrl: https://api.prismacloud.io platform: Prisma Cloud status: active - name: Cloud Identity Engine API namespace: cloud-identity-engine-api version: v1 baseUrl: https://api.strata.paloaltonetworks.com platform: Strata status: active # Cortex - name: Cortex XDR API namespace: cortex-xdr-api version: v1 baseUrl: https://api-{fqdn}/public_api/v1/ platform: Cortex status: active - name: Cortex XSOAR API namespace: cortex-xsoar-api version: v1 baseUrl: https://{xsoar-server}/ platform: Cortex status: active - name: Cortex XSIAM API namespace: cortex-xsiam-api version: v1 baseUrl: https://api-{fqdn}/public_api/v1/ platform: Cortex status: active - name: Cortex Xpanse API namespace: cortex-xpanse-api version: v1 baseUrl: https://api-{fqdn}/public_api/v1/ platform: Cortex status: active # AI Security - name: Prisma AIRS AI Runtime Security API namespace: prisma-airs-api version: v1 baseUrl: https://service.api.aisecurity.paloaltonetworks.com platform: Prisma AIRS status: active - name: Prisma AIRS AI Red Teaming API namespace: prisma-airs-ai-red-teaming-api version: v1 baseUrl: https://api.sase.paloaltonetworks.com/ai-red-teaming platform: Prisma AIRS status: active # Cross-Platform - name: Security Advisory API namespace: security-advisory-api version: beta baseUrl: https://security.paloaltonetworks.com platform: Cross-Platform status: active - name: Prisma SASE Service Status API namespace: prisma-sase-service-status-api version: v2 baseUrl: https://sase.status.paloaltonetworks.com/api/v2 platform: Cross-Platform status: active - name: Cross-Platform Service Status API namespace: cross-platform-service-status-api version: v2 baseUrl: https://status.paloaltonetworks.com/api/v2 platform: Cross-Platform status: active - name: VM-Series Licensing API namespace: vm-series-licensing-api version: v1 baseUrl: https://licensing.paloaltonetworks.com platform: Strata status: active - name: Expedition API namespace: expedition-api version: v1 baseUrl: https://{expedition-vm-ip}/api/v1/ platform: Strata status: deprecated resources: # Security Operations - name: incidents description: Security incidents detected by XDR, XSIAM, or Prisma Cloud requiring investigation and response. apis: [cortex-xdr-api, cortex-xsiam-api, prisma-cloud-cspm-api] actions: [list, get, update, search] - name: alerts description: Security alerts generated by detection engines across network, cloud, and endpoint telemetry. apis: [cortex-xdr-api, cortex-xsiam-api, prisma-cloud-cspm-api, prisma-cloud-compute-api] actions: [list, get, dismiss, reopen] - name: endpoints description: Managed endpoints (workstations, servers) with XDR agents for detection and response. apis: [cortex-xdr-api, cortex-xsiam-api] actions: [list, get, isolate, unisolate, scan] - name: playbooks description: Automated response workflows in XSOAR for orchestrating security actions. apis: [cortex-xsoar-api] actions: [list, get, create, run] - name: investigations description: XSOAR investigation records linking incidents, evidence, and response actions. apis: [cortex-xsoar-api] actions: [list, get, create, search] # Network Security - name: security-rules description: Firewall security policy rules controlling traffic based on application, user, and content. apis: [pan-os-rest-api, strata-cloud-manager-api, cloud-ngfw-api] actions: [list, get, create, update, delete] - name: nat-rules description: Network address translation rules for source and destination NAT on firewalls. apis: [pan-os-rest-api, strata-cloud-manager-api] actions: [list, get, create, update, delete] - name: addresses description: Network address objects (IP, FQDN, range) used in firewall policies. apis: [pan-os-rest-api, strata-cloud-manager-api] actions: [list, get, create, update, delete] - name: address-groups description: Groups of address objects for simplified policy management. apis: [pan-os-rest-api, strata-cloud-manager-api] actions: [list, get, create, update, delete] - name: rule-stacks description: Cloud NGFW rule stacks containing security rules and associated objects. apis: [cloud-ngfw-api] actions: [list, get, create, update, delete] # Cloud Security - name: cloud-accounts description: Cloud provider accounts (AWS, Azure, GCP) onboarded for security monitoring. apis: [prisma-cloud-cspm-api] actions: [list, get, create, update, delete] - name: compliance-reports description: Compliance posture reports against standards like CIS, PCI DSS, HIPAA, SOC 2. apis: [prisma-cloud-cspm-api] actions: [list, get, generate] - name: vulnerabilities description: Software vulnerabilities discovered in cloud workloads, images, and hosts. apis: [prisma-cloud-compute-api, prisma-cloud-cspm-api] actions: [list, get, search] - name: images description: Container images scanned for vulnerabilities and compliance violations. apis: [prisma-cloud-compute-api] actions: [list, get, scan] - name: code-repositories description: Source code repositories scanned for IaC misconfigurations and secrets. apis: [prisma-cloud-code-security-api] actions: [list, get, scan] # Threat Intelligence - name: threat-signatures description: Threat prevention signatures including antivirus, anti-spyware, and vulnerability patterns. apis: [threat-vault-api] actions: [list, get, search] - name: file-submissions description: Files submitted to WildFire for malware analysis and verdict determination. apis: [wildfire-api] actions: [submit, get] - name: verdicts description: WildFire malware analysis verdicts (benign, malware, grayware, phishing). apis: [wildfire-api] actions: [get] - name: dns-lookups description: DNS domain reputation lookups for threat classification. apis: [dns-security-api] actions: [query] - name: security-advisories description: PSIRT security advisories with CVE details and remediation guidance. apis: [security-advisory-api] actions: [list, get] # SASE/Networking - name: remote-networks description: Branch and site connections to Prisma Access for secure cloud-based networking. apis: [prisma-access-api] actions: [list, get, create, update, delete] - name: service-connections description: Dedicated connections from Prisma Access to data center or cloud infrastructure. apis: [prisma-access-api] actions: [list, get, create, update, delete] - name: sites description: SD-WAN branch sites with WAN interfaces, LAN networks, and path policies. apis: [prisma-sd-wan-api] actions: [list, get, create, update, delete] - name: connectors description: ZTNA connectors providing zero trust access to private applications. apis: [ztna-connector-api] actions: [list, get, create, update, delete] # Identity/Access - name: service-accounts description: API service accounts with client credentials for OAuth 2.0 authentication. apis: [sase-iam-api] actions: [list, get, create, update, delete] - name: access-policies description: Role-based access control policies for SASE platform API authorization. apis: [sase-iam-api] actions: [list, get, create, update, delete] - name: tenants description: Tenant Service Groups (TSGs) for hierarchical multi-tenant management. apis: [sase-tenancy-service-api] actions: [list, get, create, update] - name: subscriptions description: License subscriptions allocated to tenant service groups. apis: [sase-subscription-api] actions: [list, get] # Data Protection - name: dlp-incidents description: Data loss prevention incidents with matched sensitive data patterns. apis: [dlp-api] actions: [list, get, update] - name: data-patterns description: DLP data pattern definitions for detecting sensitive content. apis: [dlp-api] actions: [list, get] - name: saas-assets description: SaaS application assets monitored for security and compliance. apis: [saas-security-api] actions: [list, get] # AI Security - name: scan-requests description: AI runtime security scan requests for analyzing prompts and model responses. apis: [prisma-airs-api] actions: [scan] - name: security-profiles description: AI security profiles configuring threat detection rules for AI applications. apis: [prisma-airs-api] actions: [list, get, create, update, delete] - name: red-team-scans description: Automated red team vulnerability scans against AI systems and LLM applications. apis: [prisma-airs-ai-red-teaming-api] actions: [create, get, list] # Monitoring - name: log-forwarding-profiles description: Configuration for forwarding security logs to SIEM and external destinations. apis: [strata-logging-service-api] actions: [list, get, create, update, delete] - name: notifications description: Multi-tenant notifications for security incidents, upgrades, and maintenance. apis: [sase-multitenant-notifications-api] actions: [list, get, create] actions: - name: list verb: GET pattern: read description: Retrieve a paginated list of resources. - name: get verb: GET pattern: read description: Retrieve a single resource by identifier. - name: create verb: POST pattern: write description: Create a new resource. - name: update verb: PUT/PATCH pattern: write description: Update an existing resource. - name: delete verb: DELETE pattern: destructive description: Remove a resource. - name: search verb: POST pattern: query/read description: Search resources with filters and date ranges. - name: query verb: POST pattern: query/read description: Execute a structured query (XQL, log query, DNS lookup). - name: scan verb: POST pattern: write description: Submit content for security scanning (malware, AI prompts, containers). - name: submit verb: POST pattern: write description: Submit files or URLs for analysis. - name: run verb: POST pattern: write description: Execute a script, playbook, or operational command. - name: isolate verb: POST pattern: destructive description: Network-isolate an endpoint for containment. - name: unisolate verb: POST pattern: write description: Remove network isolation from an endpoint. - name: dismiss verb: POST pattern: write description: Dismiss or close an alert. - name: reopen verb: POST pattern: write description: Reopen a previously dismissed alert. - name: generate verb: POST pattern: write description: Generate a report, key, or assessment. - name: push verb: POST pattern: write description: Push candidate configuration to running config. - name: login verb: POST pattern: write description: Authenticate and obtain an access token. parameters: pagination: - name: limit description: Maximum number of results per page. - name: offset description: Number of results to skip. - name: page description: Page number (alternative pagination). - name: size description: Page size (alternative pagination). time-filtering: - name: start_time description: Start of time range for filtering results. - name: end_time description: End of time range for filtering results. - name: timeAmount description: Relative time amount. - name: timeType description: Time range type (relative, absolute, to_now). - name: timeUnit description: Time unit (minute, hour, day, week, month). identifiers: - name: id description: Unique resource identifier. - name: name description: Resource name. - name: incident_id description: Incident identifier. - name: scan_id description: Scan identifier. - name: tsg_id description: Tenant Service Group identifier. - name: folder description: Configuration folder scope. filters: - name: severity description: Filter by severity level. - name: status description: Filter by resource status. - name: cloudType description: Filter by cloud provider (aws, azure, gcp, oci). - name: position description: Rule position (pre, post). - name: query description: Search query string. enums: severity: - critical - high - medium - low - informational status: - open - in_review - resolved - dismissed cloud-type: - aws - azure - gcp - oci verdict: - benign - malware - grayware - phishing service-status: - operational - degraded_performance - partial_outage - major_outage rule-position: - pre - post time-type: - relative - absolute - to_now time-unit: - minute - hour - day - week - month metric-type: - bandwidth - latency - jitter - packet_loss data-stream-type: - web - ios - android authentication: schemes: - type: apikey placement: header headers: [x-xdr-hmac-v2, x-pan-token, X-Key-Id, X-Access-Key, X-DNS-API-APIKEY] apis: [cortex-xdr-api, cortex-xsiam-api, cortex-xpanse-api, cortex-xsoar-api, prisma-airs-api, iot-security-api, dns-security-api, threat-vault-api] - type: oauth2 flow: client_credentials tokenUrl: https://auth.apps.paloaltonetworks.com/oauth2/access_token apis: [prisma-access-api, prisma-sd-wan-api, sase-iam-api, sase-tenancy-service-api, sase-subscription-api, sase-aggregate-monitoring-api, strata-logging-service-api, sase-config-orchestration-api, ztna-connector-api, prisma-access-browser-api, autonomous-dem-api, sspm-api, saas-security-api, sase-5g-manage-api, sase-5g-monitor-api, sase-multitenant-notifications-api, sase-multitenant-interconnect-api, identity-security-posture-management-api, prisma-access-insights-api, strata-cloud-manager-api, cloud-identity-engine-api] - type: bearer format: JWT loginEndpoint: /login apis: [prisma-cloud-cspm-api, prisma-cloud-compute-api, prisma-cloud-code-security-api, prisma-cloud-dspm-api, prisma-cloud-mssp-api, dlp-api, email-dlp-api] - type: iam-role platforms: [AWS IAM, Azure AD] apis: [cloud-ngfw-api] - type: none apis: [prisma-sase-service-status-api, cross-platform-service-status-api] api-patterns: - name: POST-for-reads description: All operations via POST including reads (Cortex XDR, XSIAM, Xpanse, WildFire pattern). apis: [cortex-xdr-api, cortex-xsiam-api, cortex-xpanse-api, wildfire-api] - name: candidate-push description: Make config changes then push candidate config to running config. apis: [strata-cloud-manager-api, prisma-access-api] - name: async-query description: Start async query, poll for results by job ID. apis: [cortex-xdr-api, cortex-xsiam-api, prisma-airs-api, aiops-ngfw-bpa-api] - name: folder-scoped description: Configuration scoped to organizational folders. apis: [strata-cloud-manager-api, prisma-access-api] # ============================================================ # CAPABILITY DIMENSION (from Naftiko) # How the platform is composed into customer-facing workflows # ============================================================ capability: workflows: - name: Incident Response file: capabilities/incident-response.yaml description: Investigate incidents, triage alerts, manage endpoints, execute response playbooks, and assess attack surface. apis: [cortex-xdr, cortex-xsiam, cortex-xsoar, cortex-xpanse] tools: 41 personas: [soc-analyst, incident-responder, threat-hunter] domains: [security-operations, detection-response, attack-surface] - name: Threat Intelligence file: capabilities/threat-intelligence.yaml description: Research IOCs, submit malware samples, analyze DNS threats, and track security advisories. apis: [threat-vault, wildfire, dns-security, security-advisory] tools: 21 personas: [threat-intel-analyst, malware-researcher, vulnerability-manager] domains: [threat-intelligence, malware-analysis] - name: Cloud Security Posture file: capabilities/cloud-security-posture.yaml description: Manage cloud alerts, enforce policies, monitor compliance, scan code, and assess data security. apis: [prisma-cloud-cspm, prisma-cloud-code-security, prisma-cloud-dspm, prisma-cloud-mssp] tools: 36 personas: [cloud-security-engineer, compliance-officer, mssp-operator] domains: [cloud-security, compliance, data-security] - name: Network Security Configuration file: capabilities/network-security-config.yaml description: Manage firewall objects, security rules, NAT rules, and cloud NGFW rule stacks. apis: [pan-os, strata-cloud-manager, cloud-ngfw] tools: 56 personas: [firewall-admin, network-security-engineer] domains: [network-security, firewall-management] - name: Secure Access file: capabilities/secure-access.yaml description: Manage remote networks, ZTNA connectors, SD-WAN sites, 5G security, and service provider interconnects. apis: [prisma-access, ztna-connector, prisma-sd-wan, sase-config-orchestration, sase-5g, sase-multitenant-interconnect] tools: 75 personas: [network-architect, sase-admin, sd-wan-operator] domains: [sase, sd-wan, zero-trust] - name: Data Protection file: capabilities/data-protection.yaml description: Manage DLP incidents, email violations, SaaS assets, posture checks, and identity security. apis: [dlp, email-dlp, saas-security, sspm, identity-security-posture] tools: 30 personas: [data-protection-analyst, saas-security-admin, compliance-team] domains: [data-protection, saas-security] - name: Identity and Access Management file: capabilities/identity-and-access.yaml description: Manage service accounts, access policies, tenant hierarchies, subscriptions, and identity data. apis: [sase-iam, sase-tenancy, sase-subscription, cloud-identity-engine] tools: 23 personas: [iam-admin, tenant-operator, subscription-manager] domains: [identity, access-management, tenancy] - name: Monitoring and Observability file: capabilities/monitoring-and-observability.yaml description: Track digital experience, aggregate security data, manage log forwarding, run assessments, and handle notifications. apis: [autonomous-dem, sase-aggregate-monitoring, strata-logging-service, aiops-ngfw-bpa, sase-multitenant-notifications] tools: 28 personas: [network-operations, sre, platform-engineer] domains: [monitoring, logging, observability] - name: AI Security file: capabilities/ai-security.yaml description: Scan AI model inputs and outputs for threats and red-team AI applications for vulnerabilities. apis: [prisma-airs, prisma-airs-red-teaming] tools: 13 personas: [ai-security-engineer, red-team-operator] domains: [ai-security, red-teaming] - name: Browser Security file: capabilities/browser-security.yaml description: Manage enterprise browser policies, user sessions, and deployments. apis: [prisma-access-browser] tools: 9 personas: [browser-security-admin, enterprise-it] domains: [browser-security] personas: - id: soc-analyst name: SOC Analyst description: Investigates security incidents, triages alerts, and coordinates response actions. workflows: [Incident Response] - id: incident-responder name: Incident Responder description: Executes containment, eradication, and recovery actions during security incidents. workflows: [Incident Response] - id: threat-hunter name: Threat Hunter description: Proactively searches for threats and IOCs across telemetry data. workflows: [Incident Response, Threat Intelligence] - id: threat-intel-analyst name: Threat Intelligence Analyst description: Researches threat actors, malware campaigns, and vulnerability trends. workflows: [Threat Intelligence] - id: malware-researcher name: Malware Researcher description: Analyzes suspicious files and samples for malware characteristics. workflows: [Threat Intelligence] - id: cloud-security-engineer name: Cloud Security Engineer description: Monitors and remediates cloud security misconfigurations and compliance violations. workflows: [Cloud Security Posture] - id: compliance-officer name: Compliance Officer description: Ensures cloud infrastructure meets regulatory and industry compliance standards. workflows: [Cloud Security Posture] - id: firewall-admin name: Firewall Administrator description: Manages firewall policies, objects, and configurations across physical and virtual firewalls. workflows: [Network Security Configuration] - id: network-security-engineer name: Network Security Engineer description: Designs and implements network security architectures and policies. workflows: [Network Security Configuration] - id: network-architect name: Network Architect description: Designs SASE and SD-WAN network architectures for secure remote access. workflows: [Secure Access] - id: sase-admin name: SASE Administrator description: Manages Prisma Access, SD-WAN, and ZTNA configurations for the SASE platform. workflows: [Secure Access] - id: sd-wan-operator name: SD-WAN Operator description: Manages SD-WAN sites, WAN interfaces, and path policies for branch connectivity. workflows: [Secure Access] - id: data-protection-analyst name: Data Protection Analyst description: Investigates DLP incidents and manages sensitive data protection policies. workflows: [Data Protection] - id: iam-admin name: IAM Administrator description: Manages service accounts, roles, and access policies for platform API access. workflows: [Identity and Access Management] - id: tenant-operator name: Tenant Operator description: Manages multi-tenant hierarchies and service group configurations for MSSPs. workflows: [Identity and Access Management] - id: network-operations name: Network Operations description: Monitors network health, performance, and digital experience metrics. workflows: [Monitoring and Observability] - id: platform-engineer name: Platform Engineer description: Manages logging infrastructure, integrations, and platform automation. workflows: [Monitoring and Observability] - id: ai-security-engineer name: AI Security Engineer description: Secures AI applications with runtime scanning and vulnerability assessment. workflows: [AI Security] - id: red-team-operator name: Red Team Operator description: Conducts automated adversarial testing against AI systems and LLM applications. workflows: [AI Security] - id: mssp-operator name: MSSP Operator description: Manages multi-tenant security operations at scale for managed service providers. workflows: [Cloud Security Posture, Identity and Access Management] - id: browser-security-admin name: Browser Security Admin description: Manages enterprise browser policies and secure browsing configurations. workflows: [Browser Security] domains: - name: security-operations description: Incident detection, investigation, response, and automation across endpoints, network, and cloud. resources: [incidents, alerts, endpoints, playbooks, investigations] workflows: [Incident Response] - name: threat-intelligence description: Threat research, malware analysis, IOC correlation, and vulnerability tracking. resources: [threat-signatures, file-submissions, verdicts, dns-lookups, security-advisories] workflows: [Threat Intelligence] - name: cloud-security description: Cloud security posture management, compliance monitoring, and workload protection. resources: [cloud-accounts, compliance-reports, vulnerabilities, images, code-repositories] workflows: [Cloud Security Posture] - name: network-security description: Firewall policy management, network objects, and cloud-native firewall configuration. resources: [security-rules, nat-rules, addresses, address-groups, rule-stacks] workflows: [Network Security Configuration] - name: sase description: Secure access service edge with remote networking, SD-WAN, and zero trust access. resources: [remote-networks, service-connections, sites, connectors] workflows: [Secure Access] - name: data-protection description: Data loss prevention, SaaS security monitoring, and identity security posture. resources: [dlp-incidents, data-patterns, saas-assets] workflows: [Data Protection] - name: identity description: Identity and access management, tenant hierarchies, and subscription management. resources: [service-accounts, access-policies, tenants, subscriptions] workflows: [Identity and Access Management] - name: monitoring description: Digital experience monitoring, log management, and best practice assessment. resources: [log-forwarding-profiles, notifications] workflows: [Monitoring and Observability] - name: ai-security description: AI runtime security scanning and automated red teaming for AI applications. resources: [scan-requests, security-profiles, red-team-scans] workflows: [AI Security] - name: browser-security description: Enterprise browser policy management and secure browsing. resources: [] workflows: [Browser Security] namespaces: consumed: - cortex-xdr - cortex-xsiam - cortex-xsoar - cortex-xpanse - threat-vault - wildfire - dns-security - security-advisory - prisma-cloud-cspm - prisma-cloud-code-security - prisma-cloud-dspm - prisma-cloud-mssp - pan-os - strata-cloud-manager - cloud-ngfw - prisma-access - ztna-connector - prisma-sd-wan - sase-config-orchestration - sase-5g - sase-multitenant-interconnect - dlp - email-dlp - saas-security - sspm - identity-security-posture - sase-iam - sase-tenancy - sase-subscription - cloud-identity-engine - autonomous-dem - sase-aggregate-monitoring - strata-logging-service - aiops-ngfw-bpa - sase-multitenant-notifications - prisma-airs - prisma-airs-red-teaming - prisma-access-browser - prisma-access-insights - prisma-cloud-compute - iot-security binds: - name: PALO_ALTO_OAUTH_TOKEN description: OAuth 2.0 access token for SASE platform APIs. workflows: [Secure Access, Identity and Access Management, Monitoring and Observability, Data Protection, Network Security Configuration] - name: PALO_ALTO_XDR_API_KEY description: API key for Cortex XDR and XSIAM authentication. workflows: [Incident Response] - name: PALO_ALTO_XSOAR_API_KEY description: API key for Cortex XSOAR authentication. workflows: [Incident Response] - name: PALO_ALTO_XPANSE_API_KEY description: API key for Cortex Xpanse authentication. workflows: [Incident Response] - name: PRISMA_CLOUD_JWT_TOKEN description: JWT bearer token for Prisma Cloud APIs. workflows: [Cloud Security Posture] - name: PALO_ALTO_AIRS_TOKEN description: API key or OAuth token for Prisma AIRS APIs. workflows: [AI Security] - name: PALO_ALTO_PAN_OS_API_KEY description: PAN-OS API key for firewall and Panorama management. workflows: [Network Security Configuration] - name: PALO_ALTO_DLP_TOKEN description: Bearer token for Enterprise DLP APIs. workflows: [Data Protection] - name: PALO_ALTO_THREAT_VAULT_KEY description: API key for Threat Vault threat intelligence queries. workflows: [Threat Intelligence] - name: PALO_ALTO_WILDFIRE_KEY description: API key for WildFire malware analysis submissions. workflows: [Threat Intelligence] # ============================================================ # CROSS-REFERENCE # Maps operational resources to capability workflows # ============================================================ crossReference: - resource: incidents operations: [list, get, update, search] workflows: [Incident Response, Cloud Security Posture] personas: [soc-analyst, incident-responder, cloud-security-engineer] - resource: alerts operations: [list, get, dismiss, reopen] workflows: [Incident Response, Cloud Security Posture] personas: [soc-analyst, cloud-security-engineer] - resource: endpoints operations: [list, get, isolate, unisolate, scan] workflows: [Incident Response] personas: [soc-analyst, incident-responder] - resource: playbooks operations: [list, get, create, run] workflows: [Incident Response] personas: [soc-analyst, incident-responder] - resource: security-rules operations: [list, get, create, update, delete] workflows: [Network Security Configuration] personas: [firewall-admin, network-security-engineer] - resource: addresses operations: [list, get, create, update, delete] workflows: [Network Security Configuration] personas: [firewall-admin, network-security-engineer] - resource: rule-stacks operations: [list, get, create, update, delete] workflows: [Network Security Configuration] personas: [firewall-admin] - resource: cloud-accounts operations: [list, get, create, update, delete] workflows: [Cloud Security Posture] personas: [cloud-security-engineer] - resource: compliance-reports operations: [list, get, generate] workflows: [Cloud Security Posture] personas: [compliance-officer, cloud-security-engineer] - resource: vulnerabilities operations: [list, get, search] workflows: [Cloud Security Posture] personas: [cloud-security-engineer] - resource: threat-signatures operations: [list, get, search] workflows: [Threat Intelligence] personas: [threat-intel-analyst] - resource: file-submissions operations: [submit, get] workflows: [Threat Intelligence] personas: [malware-researcher] - resource: verdicts operations: [get] workflows: [Threat Intelligence] personas: [malware-researcher, threat-intel-analyst] - resource: remote-networks operations: [list, get, create, update, delete] workflows: [Secure Access] personas: [network-architect, sase-admin] - resource: sites operations: [list, get, create, update, delete] workflows: [Secure Access] personas: [sd-wan-operator, sase-admin] - resource: connectors operations: [list, get, create, update, delete] workflows: [Secure Access] personas: [sase-admin] - resource: service-accounts operations: [list, get, create, update, delete] workflows: [Identity and Access Management] personas: [iam-admin] - resource: tenants operations: [list, get, create, update] workflows: [Identity and Access Management] personas: [tenant-operator, mssp-operator] - resource: dlp-incidents operations: [list, get, update] workflows: [Data Protection] personas: [data-protection-analyst] - resource: scan-requests operations: [scan] workflows: [AI Security] personas: [ai-security-engineer] - resource: red-team-scans operations: [create, get, list] workflows: [AI Security] personas: [red-team-operator] - resource: log-forwarding-profiles operations: [list, get, create, update, delete] workflows: [Monitoring and Observability] personas: [platform-engineer, network-operations] - resource: notifications operations: [list, get, create] workflows: [Monitoring and Observability] personas: [platform-engineer]