# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity Exposure Deviance API version: 1.0.0 extends: openapi/tenable-deviance-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 12 - target: $.paths['/api/deviances/changed'].get update: x-apievangelist-phrasing: intent: List deviances created or resolved since an event effect: read questions: - Which deviances appeared or got resolved since the last event I processed? - Can I poll for newly created and resolved deviances incrementally? instructions: - text: List deviances created or resolved since the last event. - text: Show changed deviances since my last sync. method: generated generated: '2026-10-01' - target: $.paths['/api/directories/{directoryId}/deviances/{id}'].get update: x-apievangelist-phrasing: intent: Get a deviance history entry in a directory effect: read questions: - How do I look up one deviance history record by id within a directory? - What is the history of a single deviance in a domain? instructions: - text: Get deviance {id} in directory {directoryId}. slots: id: path.id directoryId: path.directoryId - text: Show history record {id} for directory {directoryId}, no forest needed. slots: id: path.id directoryId: path.directoryId method: generated generated: '2026-10-01' - target: $.paths['/api/export/profiles/{profileId}/checkers/{checkerId}'].get update: x-apievangelist-phrasing: intent: Export a checker's deviant objects as CSV effect: read questions: - Can I download all AD objects failing an indicator as CSV? - How do I export deviances for one checker in my language? instructions: - text: Export deviant objects for checker {checkerId} in profile {profileId} as CSV. slots: checkerId: path.checkerId profileId: path.profileId - text: Download the checker {checkerId} deviance CSV for profile {profileId} in {language}. slots: checkerId: path.checkerId profileId: path.profileId language: query.language method: generated generated: '2026-10-01' - target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances'].get update: x-apievangelist-phrasing: intent: List deviances in a directory effect: read questions: - Which deviances exist across one domain, regardless of checker? - Can I page through only resolved deviances for a directory? instructions: - text: List deviances for directory {directoryId} in forest {infrastructureId}. slots: directoryId: path.directoryId infrastructureId: path.infrastructureId - text: Show resolved={resolved} deviances in directory {directoryId} of forest {infrastructureId}. slots: resolved: query.resolved directoryId: path.directoryId infrastructureId: path.infrastructureId method: generated generated: '2026-10-01' - target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances/{id}'].get update: x-apievangelist-phrasing: intent: Get a deviance history entry in a forest effect: read questions: - How do I read one deviance record when I know its forest and domain? - When was a specific deviance in a forest's directory first seen? instructions: - text: Get deviance {id} in directory {directoryId} of forest {infrastructureId}. slots: id: path.id directoryId: path.directoryId infrastructureId: path.infrastructureId - text: Show deviance history {id} from infrastructure {infrastructureId}, domain {directoryId}. slots: id: path.id directoryId: path.directoryId infrastructureId: path.infrastructureId method: generated generated: '2026-10-01' - target: $.paths['/api/infrastructures/{infrastructureId}/directories/{directoryId}/deviances/{id}'].patch update: x-apievangelist-phrasing: intent: Ignore one deviance until a date effect: write questions: - Can I snooze a single deviance until a certain date? - How do I ignore one specific deviance temporarily? instructions: - text: Ignore deviance {id} in directory {directoryId} of forest {infrastructureId} until {ignoreUntil}. slots: id: path.id directoryId: path.directoryId infrastructureId: path.infrastructureId ignoreUntil: requestBody.ignoreUntil - text: Snooze deviance {id} in {infrastructureId}/{directoryId} until {ignoreUntil}. slots: id: path.id directoryId: path.directoryId infrastructureId: path.infrastructureId ignoreUntil: requestBody.ignoreUntil method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/infrastructures/{infrastructureId}/directories/{directoryId}/checkers/{checkerId}/deviances'].get update: x-apievangelist-phrasing: intent: List a checker's deviances in one directory effect: read questions: - Which deviances does one indicator raise in a single domain? - Can I narrow a checker's findings to one directory? instructions: - text: List deviances of checker {checkerId} in directory {directoryId}, forest {infrastructureId}, profile {profileId}. slots: checkerId: path.checkerId directoryId: path.directoryId infrastructureId: path.infrastructureId profileId: path.profileId - text: Show page {page} of checker {checkerId} findings for domain {directoryId} in {infrastructureId} under profile {profileId}. slots: page: query.page checkerId: path.checkerId directoryId: path.directoryId infrastructureId: path.infrastructureId profileId: path.profileId method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/deviances'].post update: x-apievangelist-phrasing: intent: Query deviances for a checker effect: read questions: - How do I get all deviances an indicator raised across every domain? - Can I filter a checker's deviances with an expression? instructions: - text: Get deviances for checker {checkerId} in profile {profileId} matching {expression}. slots: checkerId: path.checkerId profileId: path.profileId expression: requestBody.expression - text: Query all directories for checker {checkerId} deviances in profile {profileId} using filter {expression}. slots: checkerId: path.checkerId profileId: path.profileId expression: requestBody.expression method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/deviances'].patch update: x-apievangelist-phrasing: intent: Ignore all deviances of a checker effect: write questions: - Can I ignore every deviance from one indicator until a date? - How do I bulk-snooze a checker's findings for a profile? instructions: - text: Ignore all deviances of checker {checkerId} in profile {profileId} until {ignoreUntil}. slots: checkerId: path.checkerId profileId: path.profileId ignoreUntil: requestBody.ignoreUntil - text: Bulk snooze checker {checkerId} findings under profile {profileId} until {ignoreUntil}. slots: checkerId: path.checkerId profileId: path.profileId ignoreUntil: requestBody.ignoreUntil method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/{adObjectId}/deviances'].post update: x-apievangelist-phrasing: intent: Search a checker's deviances on one AD object effect: read questions: - What deviances has a single AD object accumulated for one indicator? - Can I see deviance history on an object within a date range? instructions: - text: Search deviances on AD object {adObjectId} for checker {checkerId} in profile {profileId}, ignored {showIgnored}. slots: adObjectId: path.adObjectId checkerId: path.checkerId profileId: path.profileId showIgnored: requestBody.showIgnored - text: Show object {adObjectId} deviances for checker {checkerId}, profile {profileId}, from {dateStart} to {dateEnd}. slots: adObjectId: path.adObjectId checkerId: path.checkerId profileId: path.profileId dateStart: requestBody.dateStart dateEnd: requestBody.dateEnd method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/checkers/{checkerId}/ad-objects/{adObjectId}/deviances'].patch update: x-apievangelist-phrasing: intent: Ignore a checker's deviances on one AD object effect: write questions: - How do I ignore the deviances one indicator raised on a single object? - Can I snooze an object's findings only for certain reasons? instructions: - text: Ignore checker {checkerId} deviances on object {adObjectId} in profile {profileId} until {ignoreUntil}. slots: checkerId: path.checkerId adObjectId: path.adObjectId profileId: path.profileId ignoreUntil: requestBody.ignoreUntil - text: Snooze object {adObjectId} findings for reasons {reasonIds} on checker {checkerId}, profile {profileId}, until {ignoreUntil}. slots: adObjectId: path.adObjectId reasonIds: query.reasonIds checkerId: path.checkerId profileId: path.profileId ignoreUntil: requestBody.ignoreUntil method: generated generated: '2026-10-01' - target: $.paths['/api/profiles/{profileId}/infrastructures/{infrastructureId}/directories/{directoryId}/events/{eventId}/deviances'].post update: x-apievangelist-phrasing: intent: List deviances caused by an event effect: read questions: - Which deviances did a specific AD change event introduce? - Can I filter an event's deviances by checker and reason? instructions: - text: Get deviances from event {eventId} in directory {directoryId}, forest {infrastructureId}, profile {profileId} for checkers {checkers} and reasons {reasons}. slots: eventId: path.eventId directoryId: path.directoryId infrastructureId: path.infrastructureId profileId: path.profileId checkers: requestBody.checkers reasons: requestBody.reasons - text: Show what event {eventId} broke in {infrastructureId}/{directoryId} under profile {profileId}. slots: eventId: path.eventId directoryId: path.directoryId infrastructureId: path.infrastructureId profileId: path.profileId method: generated generated: '2026-10-01'