# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Admin Portal Account API version: 1.0.0 extends: openapi/strivacity-account-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 27 - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts'].get update: x-apievangelist-phrasing: intent: List accounts in an identity store effect: read questions: - Which accounts in my identity store have never logged in? - Can I filter customer accounts by email, organization or role? - How do I find accounts created or disabled within a date range? instructions: - text: List all accounts in identity store {store}. slots: store: path.identityStoreName - text: Find accounts in {store} whose email is {email}. slots: store: path.identityStoreName email: query.emailNativeClaim - text: Show accounts in {store} that have never logged in. slots: store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts'].post update: x-apievangelist-phrasing: intent: Create a customer account effect: write questions: - How do I create a new user account in a Strivacity identity store? - Can I migrate a user with a password hash from a legacy store? - Is it possible to create an account without sending email verification? instructions: - text: Create an account in {store} with email {email} and language {language}. slots: store: path.identityStoreName email: requestBody.email language: requestBody.language - text: Create an account for phone {phone} in identity store {store}, language {language}. slots: store: path.identityStoreName phone: requestBody.phone language: requestBody.language method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}'].get update: x-apievangelist-phrasing: intent: Get an account's details effect: read questions: - What details are stored on a single customer account? - Can I look up one account by its ID? instructions: - text: Get account {account} from identity store {store}. slots: account: path.accountId store: path.identityStoreName - text: Show me the profile of account {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}'].delete update: x-apievangelist-phrasing: intent: Delete an account effect: destructive questions: - How do I permanently delete a user account? - Can I remove a customer account from an identity store? instructions: - text: Delete account {account} from identity store {store}. slots: account: path.accountId store: path.identityStoreName - text: Permanently remove user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/authenticators'].post update: x-apievangelist-phrasing: intent: Add an email or phone authenticator effect: write questions: - How do I add a phone number as an MFA authenticator for a user? - Can I register an email authenticator on someone's account? - Which authenticator types can an admin add to an account? instructions: - text: Add a {type} authenticator with target {target} to account {account} in {store}. slots: type: requestBody.type target: requestBody.target account: path.accountId store: path.identityStoreName - text: Register phone authenticator {target} for user {account} in {store}. slots: target: requestBody.target account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/authenticators/{authenticatorId}'].delete update: x-apievangelist-phrasing: intent: Remove an authenticator from an account effect: destructive questions: - How do I remove an MFA authenticator from a user's account? - Can an admin delete a lost phone authenticator for a customer? instructions: - text: Delete authenticator {authenticator} from account {account} in {store}. slots: authenticator: path.authenticatorId account: path.accountId store: path.identityStoreName - text: Remove the authenticator {authenticator} that user {account} no longer has, in {store}. slots: authenticator: path.authenticatorId account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/disable'].post update: x-apievangelist-phrasing: intent: Disable an account effect: destructive questions: - How do I disable a user so they can no longer sign in? - Can I suspend an account without deleting it? instructions: - text: Disable account {account} in identity store {store}. slots: account: path.accountId store: path.identityStoreName - text: Suspend user {account} in {store} without deleting them. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/enable'].post update: x-apievangelist-phrasing: intent: Re-enable a disabled account effect: write questions: - How do I re-enable an account that was disabled? - Can a suspended user be reactivated? instructions: - text: Enable account {account} in identity store {store}. slots: account: path.accountId store: path.identityStoreName - text: Reactivate the disabled user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/groups'].post update: x-apievangelist-phrasing: intent: Assign groups to an account effect: write questions: - How do I put a user into one or more groups at once? - What permissions do I need to assign groups to an account? instructions: - text: Assign groups to account {account} in identity store {store}. slots: account: path.accountId store: path.identityStoreName - text: Add user {account} in {store} to the groups I list. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/identities/identifier'].post update: x-apievangelist-phrasing: intent: Change an account's login identifier effect: write questions: - How do I change the email or username a user logs in with? - Can I update an account identifier without triggering verification? instructions: - text: Change the {type} identifier of account {account} in {store} to {identifier}. slots: type: requestBody.type account: path.accountId store: path.identityStoreName identifier: requestBody.identifier - text: Update the login identifier for user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/impersonation'].post update: x-apievangelist-phrasing: intent: Impersonate an account for support effect: write questions: - How can a support agent impersonate a customer to troubleshoot? - Does an impersonation request need a reason and a client? instructions: - text: Generate an impersonation link for account {account} in {store} via client {client} because {reason}. slots: account: path.accountId store: path.identityStoreName client: requestBody.clientId reason: requestBody.reason - text: Let me log in as user {account} in {store} for support, reason {reason}. slots: account: path.accountId store: path.identityStoreName reason: requestBody.reason method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/liftPasscodeLock'].post update: x-apievangelist-phrasing: intent: Unlock an account locked by passcode attempts effect: write questions: - How do I unlock a user who failed too many one-time passcode attempts? - Can an admin clear a passcode lock on an account? instructions: - text: Lift the passcode lock on account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Unlock user {account} in {store} after too many OTP failures. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/liftPasswordLock'].post update: x-apievangelist-phrasing: intent: Unlock an account locked by password attempts effect: write questions: - How do I unlock a user who is locked out after wrong passwords? - Can I lift a password lockout for a customer? instructions: - text: Lift the password lock on account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Unlock user {account} in {store} after too many wrong passwords. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/lock'].post update: x-apievangelist-phrasing: intent: Lock an account effect: write questions: - How do I put a lock on a suspicious user account? - Which lock types can an admin set on an account? instructions: - text: Set a {type} lock on account {account} in {store}. slots: type: requestBody.type account: path.accountId store: path.identityStoreName - text: Lock user {account} in identity store {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/notificationPreferences'].put update: x-apievangelist-phrasing: intent: Update an account's notification preferences effect: write questions: - How do I stop a user from getting password reset success emails? - Which notifications can be switched on or off for one account? instructions: - text: Update notification preferences for account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Turn off account lockout notifications for user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/organization'].put update: x-apievangelist-phrasing: intent: Move an account to another organization effect: write questions: - How do I move a user to a different organization? - Can I change which organization an account belongs to? instructions: - text: Move account {account} in {store} to organization {organization}. slots: account: path.accountId store: path.identityStoreName organization: requestBody.id - text: Change the organization of user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/password/change'].post update: x-apievangelist-phrasing: intent: Set a new password for an account effect: write questions: - How do I set a new password directly on a user's account? - Can an admin change a password and bypass the password policy? instructions: - text: Change the password of account {account} in {store} to {password}. slots: account: path.accountId store: path.identityStoreName password: requestBody.newPassword - text: Set a new password hash for user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/password/reset'].post update: x-apievangelist-phrasing: intent: Send a password reset email to a user effect: write questions: - How do I trigger a password reset email for a customer? - Can an admin start a password reset on behalf of a user? instructions: - text: Send a password reset email to account {account} in {store} via application {app}. slots: account: path.accountId store: path.identityStoreName app: header.X-Notification-By-Application - text: Request a password reset for user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/personal'].put update: x-apievangelist-phrasing: intent: Update an account's profile attributes effect: write questions: - How do I update profile attributes like name or address on an account? - Does updating account metadata overwrite attributes I don't send? instructions: - text: Update the profile attributes of account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Change the stored metadata for user {account} in identity store {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/provisions'].get update: x-apievangelist-phrasing: intent: List an account's provisioning statuses effect: read questions: - Has this user been provisioned to my downstream systems yet? - Where can I see outbound provisioning status for one account? instructions: - text: List provisioning statuses for account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Show which provision targets user {account} in {store} synced to. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/provisions/{outboundProvisionId}/sync'].post update: x-apievangelist-phrasing: intent: Prioritize an account's provisioning sync effect: write questions: - How do I push one user to a provisioning target right away? - Can I make an outbound provision sync an account with higher priority? instructions: - text: Prioritize syncing account {account} in {store} to provision target {target}. slots: account: path.accountId store: path.identityStoreName target: path.outboundProvisionId - text: Resync user {account} in {store} to outbound provision {target} now. slots: account: path.accountId store: path.identityStoreName target: path.outboundProvisionId method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/roles'].get update: x-apievangelist-phrasing: intent: List an account's organization roles effect: read questions: - What organization roles does this user currently hold? - Can I see every role assignment for one account? instructions: - text: List role assignments for account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Show the organization roles held by user {account} in {store}. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/roles'].post update: x-apievangelist-phrasing: intent: Assign organization roles to an account effect: write questions: - How do I give a user admin roles within an organization? - Can I assign several roles to an account in one call? instructions: - text: Assign roles {roles} in organization {organization} to account {account} in {store}. slots: roles: requestBody.roles organization: requestBody.organization account: path.accountId store: path.identityStoreName - text: Grant user {account} in {store} the roles {roles} for organization {organization}. slots: account: path.accountId store: path.identityStoreName roles: requestBody.roles organization: requestBody.organization method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/roles/{roleId}'].delete update: x-apievangelist-phrasing: intent: Remove an organization role from an account effect: destructive questions: - How do I revoke a role a user has in an organization? - Can I take one organization role away from an account? instructions: - text: Remove role {role} in organization {organization} from account {account} in {store}. slots: role: path.roleId organization: query.organization account: path.accountId store: path.identityStoreName - text: Revoke role {role} for user {account} in {store} within organization {organization}. slots: role: path.roleId account: path.accountId store: path.identityStoreName organization: query.organization method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/sessions'].get update: x-apievangelist-phrasing: intent: List an account's active sessions effect: read questions: - Which devices and browsers is this user currently signed in on? - Can I see a customer's active login sessions? instructions: - text: List sessions for account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Show where user {account} in {store} is logged in. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/sessions'].delete update: x-apievangelist-phrasing: intent: Log an account out everywhere effect: destructive questions: - How do I sign a user out of every browser at once? - Does clearing sessions perform a back-channel logout? instructions: - text: Clear all sessions for account {account} in {store}. slots: account: path.accountId store: path.identityStoreName - text: Log user {account} in {store} out of every device. slots: account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01' - target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/sessions/{sessionId}'].delete update: x-apievangelist-phrasing: intent: End one session for an account effect: destructive questions: - How do I end just one of a user's sessions? - Can I revoke a single device session without logging out the rest? instructions: - text: Delete session {session} for account {account} in {store}. slots: session: path.sessionId account: path.accountId store: path.identityStoreName - text: End only session {session} of user {account} in {store}. slots: session: path.sessionId account: path.accountId store: path.identityStoreName method: generated generated: '2026-10-01'