# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity Exposure AD object API version: 1.0.0 extends: openapi/tenable-ad-object-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 7 - target: $.paths['/api/ad-objects'].get update: x-apievangelist-phrasing: intent: List every AD object's latest state effect: read questions: - Can I pull the last known state of every Active Directory object at once? - How do I export all AD objects Identity Exposure has collected? instructions: - text: List the latest state of every AD object. - text: Dump all ad-objects as of the current timestamp. method: generated generated: '2026-10-01' - target: $.paths['/api/directories/{directoryId}/ad-objects/{id}'].get update: x-apievangelist-phrasing: intent: Get an AD object in a directory effect: read questions: - How do I look up one AD object by id within a directory? - What attributes does a given AD object currently have in its directory? instructions: - text: Get AD object {id} from directory {directoryId}. slots: id: path.id directoryId: path.directoryId - text: Show object {id} in directory {directoryId} without naming the forest. slots: id: path.id directoryId: path.directoryId method: generated generated: '2026-10-01' - target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/ad-objects/{id}'].get update: x-apievangelist-phrasing: intent: Get an AD object within a forest's directory effect: read questions: - Can I fetch an AD object by id when I know its forest and domain? - Which call returns an AD object scoped to a specific infrastructure and directory? instructions: - text: Get AD object {id} in directory {directoryId} of forest {infrastructureId}. slots: id: path.id directoryId: path.directoryId infrastructureId: path.infrastructureId - text: Fetch object {id} from infrastructure {infrastructureId}, domain {directoryId}. slots: id: path.id directoryId: path.directoryId infrastructureId: path.infrastructureId method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/{id}'].get update: x-apievangelist-phrasing: intent: Get a deviant AD object for a checker effect: read questions: - How do I see why one AD object fails a specific indicator of exposure? - Can I include ignored deviances when viewing an object flagged by a checker? instructions: - text: Get AD object {id} flagged by checker {checkerId} in profile {profileId}. slots: id: path.id checkerId: path.checkerId profileId: path.profileId - text: 'Show object {id} for checker {checkerId} in profile {profileId}, ignored deviances included: {showIgnored}.' slots: id: path.id checkerId: path.checkerId profileId: path.profileId showIgnored: query.showIgnored method: generated generated: '2026-10-01' - target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/events/{eventId}/ad-objects/{id}'].get update: x-apievangelist-phrasing: intent: Get an AD object as of an event effect: read questions: - Can I see what an AD object looked like at the time of a particular event? - What was an object's state when a given AD change event happened? instructions: - text: Get AD object {id} as recorded in event {eventId} of directory {directoryId}, forest {infrastructureId}. slots: id: path.id eventId: path.eventId directoryId: path.directoryId infrastructureId: path.infrastructureId - text: Show the snapshot of object {id} at event {eventId} in directory {directoryId} of forest {infrastructureId}. slots: id: path.id eventId: path.eventId directoryId: path.directoryId infrastructureId: path.infrastructureId method: generated generated: '2026-10-01' - target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/events/{eventId}/ad-objects/{id}/changes'].get update: x-apievangelist-phrasing: intent: See what changed on an AD object in an event effect: read questions: - Which attributes changed on an AD object between an event and the one before it? - How do I diff an object's values before and after a change event? instructions: - text: Show the attribute changes on object {id} in event {eventId}, directory {directoryId}, forest {infrastructureId}. slots: id: path.id eventId: path.eventId directoryId: path.directoryId infrastructureId: path.infrastructureId - text: Diff object {id} at event {eventId} against the prior event in directory {directoryId} of {infrastructureId}, values {wantedValues}. slots: id: path.id eventId: path.eventId directoryId: path.directoryId infrastructureId: path.infrastructureId wantedValues: query.wantedValues method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/search'].post update: x-apievangelist-phrasing: intent: Search AD objects deviant for a checker effect: read questions: - Can I search which AD objects have deviances for one checker within a date range? - How do I filter flagged objects for an indicator by reason and directory? instructions: - text: 'Search objects failing checker {checkerId} in profile {profileId}: filter {expression}, directories {directories}, reasons {reasons}, ignored {showIgnored}.' slots: checkerId: path.checkerId profileId: path.profileId expression: requestBody.expression directories: requestBody.directories reasons: requestBody.reasons showIgnored: requestBody.showIgnored - text: Find objects flagged by checker {checkerId} in profile {profileId} between {dateStart} and {dateEnd}. slots: checkerId: path.checkerId profileId: path.profileId dateStart: requestBody.dateStart dateEnd: requestBody.dateEnd method: generated generated: '2026-10-01'