# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for TextQL RBAC Service API version: 1.0.0 extends: openapi/textql-rbac-service-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 37 - target: $.paths['/textql.rpc.public.rbac.RBACService/ApproveAccessRequest'].post update: x-apievangelist-phrasing: intent: Approve an access request effect: write questions: - How do I grant a teammate's pending request to access a chat or dashboard? - Can an admin approve access requests through the API? instructions: - text: Approve access request {request}. slots: request: requestBody.requestId - text: Grant the pending access request {request}. slots: request: requestBody.requestId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/AssignPermissionToRole'].post update: x-apievangelist-phrasing: intent: Add a single permission to a role effect: write questions: - How do I give a role one extra permission? - Can I add a single permission to a custom role without touching the others? instructions: - text: Add permission {permission} to role {role}. slots: permission: requestBody.permissionId role: requestBody.roleId - text: Grant role {role} the single permission {permission}. slots: role: requestBody.roleId permission: requestBody.permissionId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/AssignRoleToMember'].post update: x-apievangelist-phrasing: intent: Assign a role to a member over RPC effect: write questions: - How do I give a member a role through the RBAC service? - Can I make someone an admin by assigning them a role over Connect RPC? instructions: - text: Assign role {role} to member {member} via the RBAC service. slots: role: requestBody.roleId member: requestBody.memberId - text: Use RBAC RPC to put member {member} in role {role}. slots: member: requestBody.memberId role: requestBody.roleId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/CreateApiKey'].post update: x-apievangelist-phrasing: intent: Create an API key for a member effect: write questions: - How do I issue an API key on behalf of another member? - Can I create a key that expires and only assumes certain roles? instructions: - text: Create an API key named {name} for member {member}. slots: name: requestBody.name member: requestBody.targetMemberId - text: Issue an API key {name} for member {member} that expires in {expiry_seconds} seconds. slots: name: requestBody.name member: requestBody.targetMemberId expiry_seconds: requestBody.expirySeconds method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/CreatePersonalApiKey'].post update: x-apievangelist-phrasing: intent: Create a personal API key effect: write questions: - How do I create an API key for myself? - Can my personal key be limited to just some of my roles? instructions: - text: Create a personal API key named {name}. slots: name: requestBody.name - text: Make me a personal key {name} that expires after {expiry_seconds} seconds and assumes roles {roles}. slots: name: requestBody.name expiry_seconds: requestBody.expirySeconds roles: requestBody.assumedRoles method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/CreateRole'].post update: x-apievangelist-phrasing: intent: Create a role over RPC effect: write questions: - How do I define a new custom role through the RBAC service? - Can I add a description to a role when I create it over Connect RPC? instructions: - text: Create an RBAC-service role named {name}. slots: name: requestBody.name - text: Via RBAC RPC, create role {name} described as {description}. slots: name: requestBody.name description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/CreateServiceAccount'].post update: x-apievangelist-phrasing: intent: Create a service account effect: write questions: - How do I set up a non-human service account for automation? - Can a service account be created with roles already assigned and an owner? instructions: - text: Create a service account named {name}. slots: name: requestBody.name - text: Create service account {name} owned by member {owner} with roles {roles}. slots: name: requestBody.name owner: requestBody.ownerMemberId roles: requestBody.roleIds method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/CreateServiceAccountApiKey'].post update: x-apievangelist-phrasing: intent: Create an API key for a service account effect: write questions: - How do I generate credentials for a service account? - Can a service account key be set to expire? instructions: - text: Create an API key named {name} for service account {service_account}. slots: name: requestBody.name service_account: requestBody.serviceAccountMemberId - text: Issue a key for service account {service_account} expiring in {expiry_seconds} seconds. slots: service_account: requestBody.serviceAccountMemberId expiry_seconds: requestBody.expirySeconds method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/DeleteRole'].post update: x-apievangelist-phrasing: intent: Delete a role effect: destructive questions: - How do I remove a custom role I no longer use? - Can I delete a role from my organization? instructions: - text: Delete role {role}. slots: role: requestBody.roleId - text: Remove the custom role {role} from the organization. slots: role: requestBody.roleId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/DeleteServiceAccount'].post update: x-apievangelist-phrasing: intent: Delete a service account effect: destructive questions: - How do I remove a service account that's no longer needed? - Can I decommission an automation account entirely? instructions: - text: Delete service account {member}. slots: member: requestBody.memberId - text: Decommission the service account with member ID {member}. slots: member: requestBody.memberId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/GenerateShareLink'].post update: x-apievangelist-phrasing: intent: Generate a share link for an object effect: write questions: - How do I get a shareable link to a chat or dashboard? - Can I generate a link for any object type I want to share? instructions: - text: Generate a share link for {object_type} {object}. slots: object_type: requestBody.objectType object: requestBody.objectId - text: Give me a link to share the {object_type} with ID {object}. slots: object_type: requestBody.objectType object: requestBody.objectId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/GetCurrentMemberRolesAndPermissions'].post update: x-apievangelist-phrasing: intent: Get my roles and permissions effect: read questions: - Which roles and permissions do I currently hold? - What am I allowed to do in this TextQL organization? instructions: - text: List my own roles and permissions using Connect protocol version {protocol_version}. slots: protocol_version: header.Connect-Protocol-Version - text: Show every permission granted to me through my roles, timing out after {timeout_ms} ms. slots: timeout_ms: header.Connect-Timeout-Ms method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/GetEmbedUserApiKey'].post update: x-apievangelist-phrasing: intent: Get an embed user's API key effect: read questions: - How do I get the API key for an embedded user? - Where do I fetch credentials for an embed member? instructions: - text: Get the embed user API key for member {member}. slots: member: requestBody.memberId - text: Fetch the embedded-user key belonging to member {member}. slots: member: requestBody.memberId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/GetMemberRoles'].post update: x-apievangelist-phrasing: intent: Get roles for several members effect: read questions: - Which roles do several members have, looked up in one call? - Can I check role assignments for a list of members at once? instructions: - text: Get the roles for members {members}. slots: members: requestBody.memberIds - text: Look up role assignments in bulk for member IDs {members}. slots: members: requestBody.memberIds method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/GetObjectAccess'].post update: x-apievangelist-phrasing: intent: See who has access to an object effect: read questions: - Who has access to a particular dashboard or chat? - How do I list the sharing grants on an object? instructions: - text: Show who can access {object_type} {object}. slots: object_type: requestBody.objectType object: requestBody.objectId - text: List the access grants on the {object_type} with ID {object}. slots: object_type: requestBody.objectType object: requestBody.objectId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/GetRole'].post update: x-apievangelist-phrasing: intent: Get a role effect: read questions: - How do I look up a role's name, description and model settings? - What does a specific role look like? instructions: - text: Get role {role}. slots: role: requestBody.roleId - text: Show the details of role {role}. slots: role: requestBody.roleId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/GetRolePermissions'].post update: x-apievangelist-phrasing: intent: List a role's permissions effect: read questions: - What permissions does a given role include? - How do I audit what a role is allowed to do? instructions: - text: List the permissions in role {role}. slots: role: requestBody.roleId - text: Show what role {role} grants. slots: role: requestBody.roleId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/HasObjectAccess'].post update: x-apievangelist-phrasing: intent: Check whether someone can access an object effect: read questions: - Does a particular member have access to a given dashboard? - Can I test whether a role can reach a specific object? instructions: - text: Check whether member {member} has access to {object_type} {object}. slots: member: requestBody.memberId object_type: requestBody.objectType object: requestBody.objectId - text: Tell me if role {role} can access {object_type} {object}. slots: role: requestBody.roleId object_type: requestBody.objectType object: requestBody.objectId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/ListAccessRequests'].post update: x-apievangelist-phrasing: intent: List access requests effect: read questions: - Which access requests are still pending approval? - Can I see who has asked for access to a specific object? instructions: - text: List access requests with status {status}. slots: status: requestBody.status - text: Show the access requests for {object_type} {object}. slots: object_type: requestBody.objectType object: requestBody.objectId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/ListApiKeys'].post update: x-apievangelist-phrasing: intent: List API keys effect: read questions: - Which API keys exist in my organization, including revoked ones? - How do I find the keys that belong to a service account? instructions: - text: List API keys matching {search_term}. slots: search_term: requestBody.searchTerm - text: Show the API keys for service account {service_account}, including revoked keys. slots: service_account: requestBody.serviceAccountMemberId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/ListPermissions'].post update: x-apievangelist-phrasing: intent: List all available permissions effect: read questions: - What permissions exist that I can add to roles? - Is there a catalog of every permission in the system? instructions: - text: List all available permissions using Connect protocol version {protocol_version}. slots: protocol_version: header.Connect-Protocol-Version - text: Show the full permission catalog, with a {timeout_ms} ms timeout. slots: timeout_ms: header.Connect-Timeout-Ms method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/ListRoles'].post update: x-apievangelist-phrasing: intent: List roles over RPC effect: read questions: - Which roles are defined, fetched through the RBAC service? - Can I enumerate roles with the Connect RPC interface? instructions: - text: List RBAC-service roles using Connect protocol version {protocol_version}. slots: protocol_version: header.Connect-Protocol-Version - text: Enumerate roles over RPC with a {timeout_ms} ms timeout. slots: timeout_ms: header.Connect-Timeout-Ms method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/ListServiceAccounts'].post update: x-apievangelist-phrasing: intent: List service accounts effect: read questions: - Which service accounts does my organization have? - Can I search service accounts by name? instructions: - text: List service accounts matching {search_term}. slots: search_term: requestBody.searchTerm - text: Show {page_size} service accounts per page. slots: page_size: requestBody.pageSize method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/RejectAccessRequest'].post update: x-apievangelist-phrasing: intent: Reject an access request effect: destructive questions: - How do I deny someone's request for access? - Can I give a reason when rejecting an access request? instructions: - text: Reject access request {request}. slots: request: requestBody.requestId - text: Deny access request {request} with reason {reason}. slots: request: requestBody.requestId reason: requestBody.rejectionReason method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/RemovePermissionFromRole'].post update: x-apievangelist-phrasing: intent: Remove a single permission from a role effect: destructive questions: - How do I take one permission away from a role? - Can I strip a single permission from a custom role? instructions: - text: Remove permission {permission} from role {role}. slots: permission: requestBody.permissionId role: requestBody.roleId - text: Revoke the single permission {permission} from role {role}. slots: permission: requestBody.permissionId role: requestBody.roleId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/RemoveRoleFromMember'].post update: x-apievangelist-phrasing: intent: Remove a role from a member over RPC effect: destructive questions: - How do I take a role away from someone through the RBAC service? - Can I unassign a role from a member over Connect RPC? instructions: - text: Via the RBAC service, remove role {role} from member {member}. slots: role: requestBody.roleId member: requestBody.memberId - text: Unassign role {role} from member {member} using RBAC RPC. slots: role: requestBody.roleId member: requestBody.memberId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/RequestAccess'].post update: x-apievangelist-phrasing: intent: Request access to an object effect: write questions: - How do I ask for access to a dashboard someone else owns? - Can I include a justification when requesting access? instructions: - text: Request {access_type} access to {object_type} {object}. slots: access_type: requestBody.requestedAccessType object_type: requestBody.objectType object: requestBody.objectId - text: Ask for access to {object_type} {object} with justification {justification}. slots: object_type: requestBody.objectType object: requestBody.objectId justification: requestBody.justification method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/RevokeApiKey'].post update: x-apievangelist-phrasing: intent: Revoke an API key effect: destructive questions: - How do I disable an API key that may be compromised? - Can I revoke a key so it stops working immediately? instructions: - text: Revoke API key {api_key}. slots: api_key: requestBody.apiKeyId - text: Permanently disable the API key {api_key}. slots: api_key: requestBody.apiKeyId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/RevokeObjectAccess'].post update: x-apievangelist-phrasing: intent: Revoke access to an object effect: destructive questions: - How do I stop a member from seeing a dashboard I shared? - Can I unshare an object from an entire role? instructions: - text: Revoke member {member}'s access to {object_type} {object}. slots: member: requestBody.memberId object_type: requestBody.objectType object: requestBody.objectId - text: Unshare {object_type} {object} from role {role}. slots: object_type: requestBody.objectType object: requestBody.objectId role: requestBody.roleId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/RotateApiKey'].post update: x-apievangelist-phrasing: intent: Rotate an API key effect: destructive questions: - How do I rotate an API key to get a fresh secret? - Can I replace a key's secret without creating a brand new key? instructions: - text: Rotate API key {api_key}. slots: api_key: requestBody.apiKeyId - text: Issue a new secret for API key {api_key}. slots: api_key: requestBody.apiKeyId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/SetRolePermissions'].post update: x-apievangelist-phrasing: intent: Bulk add and remove a role's permissions effect: write questions: - Can I add and remove several permissions on a role in one edit? - How do I change a role's permissions with a single audit entry? instructions: - text: On role {role}, add permissions {add} and remove permissions {remove}. slots: role: requestBody.roleId add: requestBody.addPermissionIds remove: requestBody.removePermissionIds - text: Bulk-grant permissions {add} to role {role} in one change. slots: add: requestBody.addPermissionIds role: requestBody.roleId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/ShareObject'].post update: x-apievangelist-phrasing: intent: Share an object with a member effect: write questions: - How do I share a dashboard with a specific colleague? - Can a share expire automatically after a date? instructions: - text: Share {object_type} {object} with member {member} as {access_type}. slots: object_type: requestBody.objectType object: requestBody.objectId member: requestBody.memberId access_type: requestBody.accessType - text: Give member {member} access to {object_type} {object} until {expires_at}. slots: member: requestBody.memberId object_type: requestBody.objectType object: requestBody.objectId expires_at: requestBody.expiresAt method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/ShareObjectWithRole'].post update: x-apievangelist-phrasing: intent: Share an object with a role effect: write questions: - Can I share a chat with everyone who holds a certain role? - How do I grant a whole role access to one object? instructions: - text: Share {object_type} {object} with role {role} as {access_type}. slots: object_type: requestBody.objectType object: requestBody.objectId role: requestBody.roleId access_type: requestBody.accessType - text: Grant everyone in role {role} access to {object_type} {object}. slots: role: requestBody.roleId object_type: requestBody.objectType object: requestBody.objectId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/UpdateObjectAccess'].post update: x-apievangelist-phrasing: intent: Change an existing access grant effect: write questions: - Can I downgrade someone's existing access on a shared object? - How do I extend the expiry of an access grant? instructions: - text: Change access grant {access} to {access_type}. slots: access: requestBody.accessId access_type: requestBody.accessType - text: Set access grant {access} to expire at {expires_at}. slots: access: requestBody.accessId expires_at: requestBody.expiresAt method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/UpdateObjectVisibility'].post update: x-apievangelist-phrasing: intent: Make an object public or private effect: write questions: - How do I make a dashboard visible to the whole organization? - Can I switch a shared object back to private? instructions: - text: Set the visibility of {object_type} {object} to public {is_public}. slots: object_type: requestBody.objectType object: requestBody.objectId is_public: requestBody.isPublic - text: Make {object_type} {object} private. slots: object_type: requestBody.objectType object: requestBody.objectId method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/UpdateRole'].post update: x-apievangelist-phrasing: intent: Update a role over RPC effect: write questions: - Can I restrict which models a role may use through the RBAC service? - How do I change a role's default model over Connect RPC? instructions: - text: Via RBAC RPC, rename role {role} to {name}. slots: role: requestBody.roleId name: requestBody.name - text: Set the RBAC-service default model of role {role} to {default_model}. slots: role: requestBody.roleId default_model: requestBody.defaultModel method: generated generated: '2026-10-01' - target: $.paths['/textql.rpc.public.rbac.RBACService/WhoAmI'].post update: x-apievangelist-phrasing: intent: Identify the current caller effect: read questions: - Which member or key am I authenticated as right now? - How can I confirm whose identity my API key resolves to? instructions: - text: Tell me who I am authenticated as, using Connect protocol version {protocol_version}. slots: protocol_version: header.Connect-Protocol-Version - text: Run a whoami check with a {timeout_ms} ms timeout. slots: timeout_ms: header.Connect-Timeout-Ms method: generated generated: '2026-10-01'