# Setting up the Amazon Connect agent workspace and step-by-step guides

Systems: Amazon Connect

For Amazon Connect administrators and contact center engineers who already run an instance and now need to set up what agents see.

Canonical: https://warmtransfer.net/guides/amazon-connect-agent-workspace-setup

Last verified: 2026-10-02

The Amazon Connect agent workspace combines contact controls, third-party applications, real-time recommendations from agent assist, tasks, Cases, step-by-step guides, Voice ID and Customer Profiles[^63]. Agents open it at `https://<instance name>.my.connect.aws/agent-app-v2/`[^64], while a web application can instead embed the CCP through the Amazon Connect Streams library[^60].

## Before you start

As of 2026-10-02 the AWS administrator guide titles its pages with the name Connect Customer for this service[^26]. This guide uses the name Amazon Connect throughout[^26].

- An instance whose agents already have a routing profile, since each agent is assigned to exactly one routing profile[^65] and queues are linked to agents only through a routing profile[^66].
- An AWS KMS key, or permission to create one, because enabling Customer Profiles requires one[^53].
- If you will use Cases, confirm that Cases appears in the console menu, because if it is absent it may not be available in your Region[^13].
- If you will add a third-party app, confirm that the Integrations menu appears in the console, because if it is missing, third-party apps are not available in that Region[^44].
- If you will add a third-party app, confirm that the instance uses a service-linked role, because an integration can be added only to such an instance and older instances must migrate first[^41].
- If your administrators work under custom IAM policies, they need app-integrations:CreateApplication, app-integrations:GetApplication and iam:GetRolePolicy, PutRolePolicy and DeleteRolePolicy in addition to AmazonConnect_FullAccess to add third-party apps[^2].
- By default, users assigned the Agent security profile can access the Contact Control Panel and make outbound calls[^67].

See also [Setting up an Amazon Connect instance](https://warmtransfer.net/knowledge/amazon-connect-instance-setup) and [Setting up queues and routing profiles in Amazon Connect](https://warmtransfer.net/knowledge/amazon-connect-routing-profile-setup).

## What changes by situation

- Where will agents handle contacts? Native agent workspace; CCP embedded in a CRM or custom app.
- When should a step-by-step guide appear for the agent? At contact start; At contact end; Both at start and at end.
- Do agents need a third-party web application inside the desktop? No third-party app; Yes, a web app shown in an iframe.
- Which native customer-data apps will agents use? Customer Profiles only; Customer Profiles and Cases.

## Step 1: Record the instance name and both agent URLs

### Do

Record the standalone CCP URL, `https://<instance name>.my.connect.aws/ccp-v2/`[^19].
Record the agent workspace URL, `https://<instance name>.my.connect.aws/agent-app-v2/`[^64].
If your instance is accessed through the awsapps.com domain, the agent workspace URL is `https://<instance name>.awsapps.com/connect/agent-app-v2/`[^8].

### Verify

Suggested check: sign in with an administrator login and open both URLs, and confirm that each one loads a sign-in page or the signed-in interface for the right instance.

## Step 2: Stand up the agent desktop

**Native agent workspace**

### Do

Give agents the agent workspace URL, `https://<instance name>.my.connect.aws/agent-app-v2/`[^64].
In the agent workspace, agents use the CCP to handle contacts alongside Customer Profiles, Cases and agent assist in a single application[^18].

### Verify

Suggested check: have a test agent sign in at the workspace URL and confirm that contact controls and a status selector appear.

### Rollback

Agents can still launch the standalone CCP at `https://<instance name>.my.connect.aws/ccp-v2/`[^19].

**CCP embedded in a CRM or custom app**

### Do

In the Amazon Connect console, open the instance's Application integration page and use Add Origin to allowlist every domain that will embed the CCP[^27].
Each allowlisted domain must use HTTPS[^4].
In the CRM or custom app, call `connect.core.initCCP`, which loads the pre-built CCP from the instance's ccpUrl into an iframe inside the container element your application provides[^39].
To show Customer Profiles in the same app, embed the CCP and Customer Profiles with the Amazon Connect Streams library, whether or not the pre-built CCP UI is displayed[^51].
Third-party applications are supported only in the Amazon Connect agent workspace and not in custom agent applications[^1].
AWS documents step-by-step guides as created for agents who use the Amazon Connect agent workspace[^37].

### Verify

Suggested check: open the application page and confirm that the embedded panel renders and that a test agent can sign in.
If the frame refuses to load, first confirm that the page's exact origin is allowlisted, because every embedding domain must be allowlisted[^27] and must use HTTPS[^4].

### Rollback

Suggested rollback: remove the origin from the allowlist and send agents to the standalone panel or workspace URL recorded earlier.

## Step 3: Enable Customer Profiles

### Do

In the Amazon Connect console, choose the instance alias, then Customer profiles, Enable customer profiles and Create new domain, optionally choose a dead-letter queue, choose a KMS key, and choose Submit[^52].
Enabling Customer Profiles requires creating or supplying an AWS KMS key, and all Customer Profiles data at rest is encrypted under that key[^53].
Choose the domain deliberately, because each instance can be associated with only one Customer Profiles domain, and profiles do not move if the instance is later re-pointed to a new domain[^54].
Leave Data store off unless you need it, because it cannot be turned off once enabled and it does not populate the agent workspace[^23].

### Verify

Suggested check: place a test contact on the instance.
Once Customer Profiles is enabled, each new contact creates a customer profile record that tracks contact history by phone number for voice or by email address for chat[^50].

### Rollback

This step can be only partly reversed: you can re-point the instance to a different domain, but existing profiles do not move with it[^54].
Data store cannot be turned off once it is enabled[^23].

## Step 4: Enable Cases if chosen, and grant agent permissions

**Customer Profiles only**

### Do

In the agents' security profile, grant Access Contact Control Panel (API name BasicAgentAccess)[^17].
Grant Customer profiles - View (CustomerProfiles.View) so that agents see profiles in the agent workspace, and grant Edit (CustomerProfiles.Edit) and Create (CustomerProfiles.Create) separately if agents should change or add profiles[^49].
Grant Agent Applications - Custom views (API name CustomViews.Access), because agents see step-by-step guides in the agent workspace only with that permission[^30].

### Verify

Suggested check: have a test agent take a test contact and confirm that a customer record appears for it.

### Rollback

Suggested rollback: clear the permissions you added and save the security profile.

**Customer Profiles and Cases**

### Do

Cases requires Customer Profiles to be enabled on the instance first[^15].
In the console, under the instance's Applications section, choose Cases, Enable cases and Add domain, and enter a unique friendly name[^13].
If Cases is absent from the menu, it may not be available in the Region[^13].
After the Cases domain exists, assign security profile permissions, create case fields, and create the case templates that agents complete in the agent workspace[^14].
In the agents' security profile, grant Access Contact Control Panel (API name BasicAgentAccess)[^17].
Grant Customer profiles - View, and Edit and Create if needed, because users of Cases also need Customer Profiles permissions[^49][^16].
Grant Cases - View, Edit and Create (Cases.View, Cases.Edit, Cases.Create)[^11].
If agents will assign case ownership, grant view permissions on queues, quick connects and users[^16].
Grant Agent Applications - Custom views (API name CustomViews.Access), because agents see step-by-step guides in the agent workspace only with that permission[^30].

### Verify

Suggested check: confirm that the case domain shows as created and that a case template is listed.
Suggested check: have a test agent take a test contact, confirm that the customer record appears, create a case from the contact, and assign it to a queue.

### Rollback

A Cases domain is deleted with the DeleteDomain API rather than through the console procedure[^12].
Suggested rollback: clear the case permissions you added and save the security profile.

## Step 5: Grant guide builders their permissions

### Do

Give the managers and business analysts who build step-by-step guides the Channels and flows - Views security profile permission plus Flows - Edit and Create[^32].

### Verify

Suggested check: have a builder open a flow, add the block that shows a view, and select a view.

### Rollback

Suggested rollback: remove the permissions you added and save the security profile.

## Step 6: Raise the concurrent active chats quota

**At contact start**

### Do

Running a step-by-step guide flow with a Show view block creates a separate chat contact with its own contact record[^35].
AWS recommends raising the concurrent active chats per instance quota by the number of concurrent contacts that will use step-by-step guides[^33].

### Verify

Suggested check: confirm that the raised quota value is granted before go-live.

**At contact end**

### Do

Running a step-by-step guide flow with a Show view block creates a separate chat contact with its own contact record[^35].
AWS recommends raising the concurrent active chats per instance quota by the number of concurrent contacts that will use step-by-step guides[^33].

### Verify

Suggested check: confirm that the raised quota value is granted before go-live.

**Both at start and at end**

### Do

AWS recommends raising the concurrent active chats per instance quota by the number of concurrent contacts that will use step-by-step guides[^33].
Size the increase at 2 per guided contact, because when both a DefaultFlowID and a DisconnectFlowID guide are set, they count as 2 active chat contacts against the quota[^9].

### Verify

Suggested check: confirm that the raised quota value is granted before go-live.

## Step 7: Build the guide flow

### Do

Create the guide as its own flow: AWS's getting-started walkthrough keeps the guide flow separate from the handler (inbound) flow that customers are routed to, and warns against sending contacts directly to the guide flow[^34].
Use the Show view block, which can be used in the Inbound flow type and not in customer hold, customer whisper, outbound whisper, agent hold, agent whisper, transfer to agent or transfer to queue flows[^58].
Choose an AWS managed view: Detail (commonly a screen pop at call start), List, Form, Confirmation or Cards[^46].
Wire the branches for the actions the agent takes in the view, and also the Error and Timeout branches[^57].
If an error branch routes back to an earlier point, add a Loop block to cap retries, which AWS recommends because otherwise the flow can run until the chat contact times out[^59].
For sensitive data, enable "This view has sensitive data" on the Show view block and turn off flow logging for that segment[^55].
Read the agent's action from $.Views.Action and the view output from $.Views.ViewResultData later in the flow[^62].
For an end-of-contact disposition guide, use a Show view block with a Form view plus a Set contact attributes block that saves the response[^25].

### Verify

Every connector must be attached to a block before a flow can be published, and Publish activates the flow immediately[^68].
Suggested check: confirm that every branch of the view block has a destination and that the flow publishes without errors.

### Rollback

The flow designer exposes previously published versions of a flow through a Latest: Published dropdown, and you roll back by opening a previous version and choosing Publish[^69].
Suggested rollback: remove the reference to the guide flow that the next step adds.

## Step 8: Attach guides to contacts

**At contact start**

### Do

In the flow that customers reach, add a Set event flow block and configure the DefaultFlowForAgentUI (Default flow for agent UI) event hook with the guide flow[^45].
To give different guides by IVR response, queue name or customer information, branch with a Check attribute block before separate Set event flow blocks[^10].
A guide flow containing a Show view block can be started this way from voice, chat, task and email contacts[^31][^56].

### Verify

A guide set with DefaultFlowForAgentUI starts as soon as the contact is offered to the agent, without waiting for the agent to accept[^36].
Suggested check: offer a test contact and confirm that the guide appears before the agent accepts it.

### Rollback

Suggested rollback: remove the event block you added and republish the inbound flow.

**At contact end**

### Do

In the flow that customers reach, add a Set event flow block and set its Disconnect flow for agent UI event to the end-of-contact guide flow[^24].
The disposition guide is surfaced after the contact ends only if DisconnectFlowForAgentUI is set before the contact ends[^25].

### Verify

Suggested check: end a test contact and confirm that the disposition form appears and that the saved attribute is on the contact record.

### Rollback

Suggested rollback: remove the event block you added and republish the inbound flow.

**Both at start and at end**

### Do

In the flow that customers reach, add a Set event flow block with the DefaultFlowForAgentUI event set to the start guide[^45].
Set the Disconnect flow for agent UI event to the end guide[^24].
The end guide is surfaced only if DisconnectFlowForAgentUI is set before the contact ends[^25].
To choose the start guide per contact, branch with a Check attribute block before the Set event flow block[^10].

### Verify

The start guide begins as soon as the contact is offered, without waiting for the agent to accept[^36].
Suggested check: end the same test contact and confirm that the end guide appears.

### Rollback

Suggested rollback: remove one or both event settings and republish the inbound flow.

## Step 9: Add any third-party app and test end to end

**Native agent workspace + No third-party app**

### Do

Run the test from AWS's getting-started walkthrough: point a phone number at the handler flow, have the agent log in to the agent workspace and go Available, then call the number so the guide displays[^61].
The test agent signs in at `https://<instance name>.my.connect.aws/agent-app-v2/`[^64].

### Verify

A start guide appears as soon as the contact is offered[^36].
The new contact creates a customer profile record[^50].
If no guide appears, check the Custom views permission, because agents see guides only with Agent Applications - Custom views[^30].
Suggested check: if you enabled case management, create a case from the test contact.

### Rollback

Suggested rollback: point the test number back at its previous flow.

**Native agent workspace + Yes, a web app shown in an iframe**

### Do

In the console, choose Integrations, then Add integration, and note that if Integrations is missing, third-party apps are not available in that Region[^44].
Choose the standard application type, which renders in an iframe and opens from the Apps launcher[^43].
Before adding the app, confirm that its Content-Security-Policy frame-ancestors allows the instance origin, because a value of same origin or deny blocks it[^29].
AWS recommends that third-party apps send `Content-Security-Policy: frame-ancestors https://*.awsapps.com https://*.my.connect.aws` so they can be embedded only in Amazon Connect[^22].
Enter an access URL that starts with https, which also applies to every approved origin unless it is localhost[^3].
Add any extra domains the app uses, such as for login flows, as approved origins so that they are included in the agent workspace Content-Security-Policy[^28].
Choose a contact scope, which sets whether the app refreshes for each contact or only for each new browser session[^21].
Associate the integration with the instance, because an integration is created once per account and Region and cannot be used by an instance until it is associated[^40].
The app must not initialize the CCP through Streams, even hidden, and must use workspace contact and agent events instead[^47].
In the agents' security profile, grant the app's access permission (API name `<app name>.Access`) together with Access Contact Control Panel[^7].
The app can take up to 10 minutes after association to appear in the Agent Applications section of the Security profiles page[^5].
Then run the test from AWS's getting-started walkthrough: point a phone number at the handler flow, have the agent log in to the agent workspace and go Available, and call the number[^61].

### Verify

A start guide appears as soon as the contact is offered[^36].
The new contact creates a customer profile record[^50].
Agents open the app from the Apps launcher with or without an active contact, and an app opened for a contact stays open until that contact closes[^6].
A pinned app opens automatically for incoming contacts and stays pinned for that user and browser until browser cookies are cleared[^48].
If the Apps launcher is missing, check Access Contact Control Panel, because without it the launcher does not appear[^7].
If no guide appears, check the Custom views permission[^30].
If the app breaks on Chrome, AWS gives setting the Enterprise policy BlockThirdPartyCookies to false as a temporary fix and app-side cookie best practices as the permanent one[^20].
Suggested check: if you enabled case management, create a case from the test contact.

### Rollback

To stop using the integration, disassociate it from the instance, and delete it only afterwards, because deleting fails while it is still associated with any instance[^42].
Suggested rollback: point the test number back at its previous flow.

**CCP embedded in a CRM or custom app + No third-party app**

### Do

Run a test call modelled on AWS's getting-started walkthrough, which points a phone number at the handler flow, has the agent log in and go Available, then calls the number[^61].
On this desktop, the agent logs in to the CCP that `connect.core.initCCP` loads into an iframe in your application[^39].

### Verify

Suggested check: confirm that the test call rings and can be answered in the embedded panel.
If you embedded Customer Profiles with the Streams library, confirm that it shows in your application[^51].
AWS documents step-by-step guides for agents who use the agent workspace, so to check the guide itself, repeat the call with the agent signed in at `https://<instance name>.my.connect.aws/agent-app-v2/`[^37][^64].

### Rollback

Suggested rollback: point the test number back at its previous flow.

**CCP embedded in a CRM or custom app + Yes, a web app shown in an iframe**

### Do

Do not expect the app to appear in your embedded desktop, because third-party applications are supported only in the Amazon Connect agent workspace and not in custom agent applications[^1].
Run a test call modelled on AWS's getting-started walkthrough, which points a phone number at the handler flow, has the agent log in and go Available, then calls the number[^61].
On this desktop, the agent logs in to the CCP that `connect.core.initCCP` loads into an iframe in your application[^39].

### Verify

Suggested check: confirm that the test call rings and can be answered in the embedded panel.
If you embedded Customer Profiles with the Streams library, confirm that it shows in your application[^51].
Do not log the missing third-party app as a defect, because such apps are not supported in custom agent applications[^1].
AWS documents step-by-step guides for agents who use the agent workspace, so to check the guide itself, repeat the call with the agent signed in at `https://<instance name>.my.connect.aws/agent-app-v2/`[^37][^64].

### Rollback

Suggested rollback: point the test number back at its previous flow.

## Applicability

As of 2026-10-02 the AWS administrator guide titles these pages Connect Customer rather than Amazon Connect[^26].
Third-party apps are not available in a Region whose console lacks the Integrations menu[^44], and Cases may not be available in a Region whose console lacks it[^13].
Applies to: Amazon Web Services Amazon Connect and Amazon Web Services Amazon Connect Customer. Deployments: multi-tenant. Sources checked 2026-10-02.

## What remains uncertain

Whether a step-by-step guide can be shown inside a custom agent application that embeds the CCP is not covered by the sources below.
AWS describes the view rendering on the agent workspace or in the customer's chat UI[^37].
Whether the console page for the CCP origin allowlist still carries the Application integration label is not covered by the sources below.
Regional availability of Customer Profiles is not covered by the sources below.
The pricing of step-by-step guides is not covered by the sources below.

## Sources

[^1]: Third-party applications are supported only in the Amazon Connect agent workspace and not in custom agent applications. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), page intro, Note. Checked 2026-10-02.
[^2]: Administrators governed by custom IAM policies need app-integrations:CreateApplication, app-integrations:GetApplication and iam:GetRolePolicy, PutRolePolicy and DeleteRolePolicy in addition to AmazonConnect_FullAccess to add third-party apps. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Required IAM permissions. Checked 2026-10-02.
[^3]: A third-party application's access URL and any approved origins must start with https unless they are localhost. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Add a third-party application, step 4, Access fields. Checked 2026-10-02.
[^4]: Domains allowlisted for embedding the CCP must use HTTPS. Source: [amazon-connect-streams README](https://github.com/amazon-connect/amazon-connect-streams/blob/master/README.md), README, Allowlisting section, closing note. Checked 2026-10-02.
[^5]: After an application is associated with an instance it can take up to 10 minutes to appear in the Agent Applications section of the Security profiles page. Source: [Assign permissions to use third-party applications](https://docs.aws.amazon.com/connect/latest/adminguide/assign-security-profile-3p-apps.html), Note. Checked 2026-10-02.
[^6]: Agents open third-party apps from the Apps launcher with or without an active contact, and an app opened for a contact stays open until that contact closes. Source: [Access third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps-agent-workspace.html), Launch third-party applications. Checked 2026-10-02.
[^7]: Agents see third-party apps only if their security profile grants access to the app (API name <app name>.Access) and the Access Contact Control Panel permission; without CCP access the Apps launcher does not appear. Source: [Access third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps-agent-workspace.html), Required security profile permissions to access third-party applications; Important things to know. Checked 2026-10-02.
[^8]: Instances accessed through the awsapps.com domain use https://<instance name>.awsapps.com/connect/agent-app-v2/ for the agent workspace. Source: [Access Connect Customer Customer Profiles in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/customer-profile-access.html), Option 1: Use Customer Profiles with the CCP out-of-the-box, Note. Checked 2026-10-02.
[^9]: When both a DefaultFlowID and a DisconnectFlowID guide are set, they count as two active chat contacts against the quota. Source: [Enable step-by-step guides in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/enable-guided-experiences-sg.html), step 3, Note. Checked 2026-10-02.
[^10]: Which guide an agent receives can be chosen per contact by branching on IVR responses, queue name or customer information with a Check attribute block before the Set event flow block. Source: [Invoke a guide at the start of a contact in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/how-to-invoke-a-flow-sg.html), example paragraph on branching logic. Checked 2026-10-02.
[^11]: Agents use Cases in the agent workspace through the Cases - View, Edit and Create permissions (Cases.View, Cases.Edit, Cases.Create). Source: [List of security profile permissions in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/security-profile-list.html), Cases table, rows Cases - Create, View, Edit. Checked 2026-10-02.
[^12]: A Cases domain is deleted with the DeleteDomain API rather than from the console procedure. Source: [Enable Cases using the Connect Customer console](https://docs.aws.amazon.com/connect/latest/adminguide/enable-cases.html), How to enable Connect Customer Cases, Tip after step 7. Checked 2026-10-02.
[^13]: Cases is enabled in the console under the instance's Applications section by choosing Cases, Enable cases, Add domain and entering a unique friendly name; if Cases is absent from the menu it may not be available in the Region. Source: [Enable Cases using the Connect Customer console](https://docs.aws.amazon.com/connect/latest/adminguide/enable-cases.html), How to enable Connect Customer Cases, steps 1-7. Checked 2026-10-02.
[^14]: After the Cases domain exists, the next steps are assigning security profile permissions, creating case fields and creating case templates that agents complete in the agent workspace. Source: [Enable Cases using the Connect Customer console](https://docs.aws.amazon.com/connect/latest/adminguide/enable-cases.html), Next steps, items 1-3. Checked 2026-10-02.
[^15]: Amazon Connect Cases requires Customer Profiles to be enabled on the instance first. Source: [Enable Cases using the Connect Customer console](https://docs.aws.amazon.com/connect/latest/adminguide/enable-cases.html), page intro, Tip. Checked 2026-10-02.
[^16]: Users of Cases also need Customer Profiles permissions, and to assign case ownership they need view permissions on queues, quick connects and users. Source: [Security profile permissions for Connect Customer Cases](https://docs.aws.amazon.com/connect/latest/adminguide/assign-security-profile-cases.html), Required Customer Profiles permissions; Required queue, quick connect, and user view permissions. Checked 2026-10-02.
[^17]: The Access Contact Control Panel permission (API name BasicAgentAccess) manages access to the CCP and is assigned to agents and to managers who monitor live conversations. Source: [List of security profile permissions in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/security-profile-list.html), Contact Control Panel (CCP) table, row Access Contact Control Panel. Checked 2026-10-02.
[^18]: In the agent workspace agents use the CCP to handle contacts alongside Customer Profiles, Cases and agent assist in a single application. Source: [Agent training guide for the Contact Control Panel (CCP) and agent workspace in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/agent-user-guide.html), Agent workspace tab, bullet list 'With the agent workspace you can access all ... features in a single application'. Checked 2026-10-02.
[^19]: The standalone Contact Control Panel (CCP) is launched at https://<instance name>.my.connect.aws/ccp-v2/. Source: [Agent training guide for the Contact Control Panel (CCP) and agent workspace in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/agent-user-guide.html), CCP tab, 'The URL to launch the CCP is'. Checked 2026-10-02.
[^20]: For third-party apps in the agent workspace on Chrome, AWS gives setting the Enterprise policy BlockThirdPartyCookies to false as a temporary fix and app-side cookie best practices as the permanent one. Source: [Access third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps-agent-workspace.html), Important things to know, first bullet. Checked 2026-10-02.
[^21]: A standard application's contact scope sets whether it refreshes for each contact or only for each new browser session. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Add a third-party application, step 4, Integration details fields. Checked 2026-10-02.
[^22]: AWS recommends that third-party apps send Content-Security-Policy: frame-ancestors https://*.awsapps.com https://*.my.connect.aws so they can be embedded only in Amazon Connect. Source: [Recommendations and best practices for Connect Customer agent workspace](https://docs.aws.amazon.com/agentworkspace/latest/devguide/recommendations-and-best-practices.html), Ensuring that apps can only be embedded in the agent workspace. Checked 2026-10-02.
[^23]: The Customer Profiles Data store cannot be turned off once enabled, and it does not populate the agent workspace. Source: [Enable Customer Profiles for your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/enable-customer-profiles.html), Before you begin, Data store. Checked 2026-10-02.
[^24]: The Set event flow block's Disconnect flow for agent UI event specifies a guide flow to invoke when a contact open in the agent workspace ends. Source: [Flow block in Connect Customer: Set event flow](https://docs.aws.amazon.com/connect/latest/adminguide/set-event-flow.html), Description, supported events list. Checked 2026-10-02.
[^25]: An end-of-contact disposition guide is a flow with a Show view block using a Form view plus a Set contact attributes block that saves the response, surfaced after the contact ends provided DisconnectFlowForAgentUI is set before the contact ends. Source: [Enable Connect Customer contact center agents to enter disposition codes when a contact ends](https://docs.aws.amazon.com/connect/latest/adminguide/disposition-codes-sg.html), first and third paragraphs. Checked 2026-10-02.
[^26]: As of 2026-10-02 the AWS administrator guide titles its pages with the name Connect Customer for the service previously titled Amazon Connect. Source: [Agent training guide for the Contact Control Panel (CCP) and agent workspace in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/agent-user-guide.html), page title. Checked 2026-10-02.
[^27]: Every domain that embeds the CCP for an instance must be allowlisted in the Amazon Connect console under the instance's Application integration page with Add Origin. Source: [amazon-connect-streams README](https://github.com/amazon-connect/amazon-connect-streams/blob/master/README.md), README, Allowlisting section, steps 1-4. Checked 2026-10-02.
[^28]: Apps that use additional domains, such as for login flows, must add them to the integration's approved origins so they are included in the agent workspace Content-Security-Policy. Source: [Recommendations and best practices for Connect Customer agent workspace](https://docs.aws.amazon.com/agentworkspace/latest/devguide/recommendations-and-best-practices.html), Using multiple domains within an app. Checked 2026-10-02.
[^29]: A third-party app can be iframed in the agent workspace only if its Content-Security-Policy frame-ancestors allows the instance origin; a value of same origin or deny blocks it. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Check whether a URL can be iframed. Checked 2026-10-02.
[^30]: Agents see step-by-step guides in the agent workspace only with the Agent Applications - Custom views permission (API name CustomViews.Access). Source: [List of security profile permissions in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/security-profile-list.html), Agent Applications table, row 'Custom views'. Checked 2026-10-02.
[^31]: A guide flow containing a Show view block can be initiated through the Set event flow block from voice, chat, task and email contacts. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), Contact types section and table. Checked 2026-10-02.
[^32]: Managers and business analysts who build step-by-step guides need the Channels and flows - Views security profile permission plus Flows - Edit and Create. Source: [Enable step-by-step guides in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/enable-guided-experiences-sg.html), step 1, Enable admins to create step-by-step guides. Checked 2026-10-02.
[^33]: AWS recommends raising the concurrent active chats per instance quota by the number of concurrent contacts that will use step-by-step guides, because guide workflows run as chat contacts. Source: [Enable step-by-step guides in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/enable-guided-experiences-sg.html), step 3, Increase your service quota for concurrent active chats per instance. Checked 2026-10-02.
[^34]: The walkthrough keeps the guide flow separate from the handler (inbound) flow that customers are routed to, and warns against sending contacts directly to the guide flow. Source: [Getting started with step-by-step guides for the Amazon Connect agent workspace](https://aws.amazon.com/blogs/contact-center/getting-started-with-step-by-step-guides-for-the-amazon-connect-agent-workspace/), flow import and handler flow sections. Checked 2026-10-02.
[^35]: Running a step-by-step guide flow with a Show view block creates a separate chat contact with its own contact record, which a Set event flow block associates with the inbound contact. Source: [Step-by-step Guides to set up your Connect Customer agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/step-by-step-guided-experiences.html), Overview section, second paragraph. Checked 2026-10-02.
[^36]: A guide set with DefaultFlowForAgentUI starts as soon as the contact is offered to the agent, without waiting for the agent to accept. Source: [Invoke a guide at the start of a contact in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/how-to-invoke-a-flow-sg.html), paragraph after the numbered steps. Checked 2026-10-02.
[^37]: The Show view block creates step-by-step guides for agents who use the Amazon Connect agent workspace; the view renders on the agent workspace or in the customer's chat UI. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), Description section, bullets. Checked 2026-10-02.
[^38]: An agent using only an embedded CCP in a CRM should not be expected to see step-by-step guides, because AWS documents guides as rendering in the agent workspace and documents no rendering path for them in a custom Streams application (inferred). Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), Description section; compare aws-connect-customer-profile-access Option 2 which names only CCP, Customer Profiles and Wisdom for Streams embedding. Checked 2026-10-02.
[^39]: connect.core.initCCP loads the pre-built CCP from the instance's ccpUrl into an iframe inside the container element the application provides. Source: [amazon-connect-streams README](https://github.com/amazon-connect/amazon-connect-streams/blob/master/README.md), README, Initialization section, connect.core.initCCP. Checked 2026-10-02.
[^40]: An integration is created once per AWS account and Region and cannot be used by an instance until it is associated with that instance. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Integration types intro; Add a third-party application, Instance association. Checked 2026-10-02.
[^41]: An integration can be added only to an instance that uses a service-linked role; older instances must migrate to one first. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Add a third-party application, Note. Checked 2026-10-02.
[^42]: To stop using an integration temporarily, disassociate it from the instance; deleting it fails while it is still associated with any instance. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Delete integrations; Troubleshooting. Checked 2026-10-02.
[^43]: The Add integration page offers three integration types: a standard application rendered in an iframe and opened from the Apps launcher, a headless service, and an MCP server. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Integration types section. Checked 2026-10-02.
[^44]: If the Integrations menu is missing from the Amazon Connect console navigation, third-party apps are not available in that AWS Region. Source: [Integrate third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps.html), Add a third-party application, step 2. Checked 2026-10-02.
[^45]: To launch a guide at the start of a contact, add a Set event flow block to the contact's flow and configure the DefaultFlowForAgentUI (Default flow for agent UI) event hook with the guide flow. Source: [Invoke a guide at the start of a contact in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/how-to-invoke-a-flow-sg.html), numbered steps 1-2. Checked 2026-10-02.
[^46]: The AWS managed views available to the Show view block are Detail (commonly a screen pop at call start), List, Form, Confirmation and Cards; customer-managed views are also supported. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), How to configure this block, Choose the view resource. Checked 2026-10-02.
[^47]: Initializing the CCP via Streams inside a third-party app, even hidden, is not supported; the app must use workspace contact and agent events instead. Source: [Recommendations and best practices for Connect Customer agent workspace](https://docs.aws.amazon.com/agentworkspace/latest/devguide/recommendations-and-best-practices.html), Initializing Streams. Checked 2026-10-02.
[^48]: A pinned app stays open while the agent is idle, opens automatically for incoming contacts, and stays pinned for that user and browser until browser cookies are cleared. Source: [Access third-party applications in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/3p-apps-agent-workspace.html), Pin apps in the agent workspace. Checked 2026-10-02.
[^49]: Agents need the Customer profiles - View permission (CustomerProfiles.View) to see profiles in the agent workspace, with Edit (CustomerProfiles.Edit) and Create (CustomerProfiles.Create) granted separately. Source: [List of security profile permissions in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/security-profile-list.html), Customer Profiles table, rows Customer profiles - Create, Edit, View. Checked 2026-10-02.
[^50]: Once Customer Profiles is enabled, each new contact creates a customer profile record that tracks contact history by phone number for voice or email address for chat. Source: [Enable Customer Profiles for your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/enable-customer-profiles.html), closing paragraph of the enable procedure ('You're done!'). Checked 2026-10-02.
[^51]: To show Customer Profiles in a custom agent application you embed the CCP and Customer Profiles with the Amazon Connect Streams library, whether or not the pre-built CCP UI is displayed. Source: [Access Connect Customer Customer Profiles in the agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/customer-profile-access.html), Option 2: Embed Customer Profiles into a custom agent application, second paragraph. Checked 2026-10-02.
[^52]: Customer Profiles is enabled in the Amazon Connect console by choosing the instance alias, then Customer profiles, Enable customer profiles, Create new domain, optional dead-letter queue, KMS key and Submit. Source: [Enable Customer Profiles for your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/enable-customer-profiles.html), Enable Customer Profiles, and specify a dead-letter queue and KMS key, steps 1-9. Checked 2026-10-02.
[^53]: Enabling Customer Profiles requires creating or supplying an AWS KMS key, under which all Customer Profiles data at rest is encrypted. Source: [Enable Customer Profiles for your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/enable-customer-profiles.html), Create a KMS key to be used by Customer Profiles to encrypt data (required). Checked 2026-10-02.
[^54]: Each Amazon Connect instance can be associated with only one Customer Profiles domain, and profiles do not move if the instance is re-pointed to a new domain. Source: [Enable Customer Profiles for your Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/enable-customer-profiles.html), Before you begin, About the customer profiles domain. Checked 2026-10-02.
[^55]: Enabling 'This view has sensitive data' on a Show view block keeps submitted data out of transcripts and contact records and hidden from agents by default; flow logging should also be turned off for that segment. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), This view has sensitive data section. Checked 2026-10-02.
[^56]: The Set event flow block supports voice, chat, task and email and can be used in all flow types. Source: [Flow block in Connect Customer: Set event flow](https://docs.aws.amazon.com/connect/latest/adminguide/set-event-flow.html), Supported channels table; Flow types section. Checked 2026-10-02.
[^57]: The Show view block branches on the action the agent takes in the view and also has Error and Timeout branches, where Timeout bounds how long the agent may take on that step without changing the customer's experience. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), Flow block branches section. Checked 2026-10-02.
[^58]: The Show view block can be used in the Inbound flow type and not in customer hold, customer whisper, outbound whisper, agent hold, agent whisper, transfer to agent or transfer to queue flows. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), Flow types table. Checked 2026-10-02.
[^59]: AWS recommends a Loop block to cap retries when a Show view error branch routes back to an earlier point, because otherwise the flow can run until the chat contact times out. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), Error scenarios, Note. Checked 2026-10-02.
[^60]: The Amazon Connect Streams library lets a web application embed the CCP UI components or handle agent and contact state events directly to build its own agent interface. Source: [Embed a custom Connect Customer Contact Control Panel (CCP)](https://docs.aws.amazon.com/connect/latest/adminguide/embed-custom-ccp.html), first paragraph. Checked 2026-10-02.
[^61]: AWS's getting-started walkthrough tests a guide by pointing a phone number at the handler flow, having the agent log in to the agent workspace and go Available, then calling the number so the guide displays. Source: [Getting started with step-by-step guides for the Amazon Connect agent workspace](https://aws.amazon.com/blogs/contact-center/getting-started-with-step-by-step-guides-for-the-amazon-connect-agent-workspace/), testing section of the walkthrough. Checked 2026-10-02.
[^62]: The Show view block writes the agent's action to $.Views.Action and the view output to $.Views.ViewResultData for use later in the flow. Source: [Flow block in Connect Customer: Show view](https://docs.aws.amazon.com/connect/latest/adminguide/show-view-block.html), Data generated by this block. Checked 2026-10-02.
[^63]: The Amazon Connect agent workspace combines contact controls, third-party applications, real-time recommendations from agent assist, tasks, case management (Cases), step-by-step guides, voice authentication (Voice ID) and customer information (Customer Profiles). Source: [Customize the Connect Customer agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/agent-workspace.html), page intro, numbered list of agent workspace parts 1-8. Checked 2026-10-02.
[^64]: Agents open the agent workspace at https://<instance name>.my.connect.aws/agent-app-v2/. Source: [Agent training guide for the Contact Control Panel (CCP) and agent workspace in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/agent-user-guide.html), Agent workspace tab, 'To access the agent workspace use the following URL'. Checked 2026-10-02.
[^65]: Each Amazon Connect agent is assigned to exactly one routing profile, while a single routing profile can have many agents assigned to it. Source: [How Connect Customer uses routing profiles](https://docs.aws.amazon.com/connect/latest/adminguide/concepts-routing.html), Opening bullet list of How Connect Customer uses routing profiles. Checked 2026-09-07.
[^66]: Queues in Amazon Connect are a waiting area for contacts and are linked to agents only through a routing profile, which also carries the channels handled and the priority and delay of each queue. Source: [How Connect Customer uses routing profiles](https://docs.aws.amazon.com/connect/latest/adminguide/concepts-routing.html), Section Routing Profiles Link Queues and Agents. Checked 2026-09-07.
[^67]: By default, users assigned the Agent security profile can access the Contact Control Panel and make outbound calls. Source: [Launch the Contact Control Panel (CCP) in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/launch-ccp.html), Bullet 'Configure permissions for the agents'. Checked 2026-09-30.
[^68]: In the flow designer, Save stores a draft of the flow and Publish activates it immediately, and every connector must be attached to a block before a flow can be published. Source: [Use the flow designer in Connect Customer to create flows](https://docs.aws.amazon.com/connect/latest/adminguide/create-contact-flow.html), Section Create an inbound flow, final numbered step and the following Note. Checked 2026-09-07.
[^69]: The flow designer exposes previously published versions of a flow through a Latest: Published dropdown, and a rollback is performed by opening a previous version and choosing Publish. Source: [Flow version control: Roll back a flow](https://docs.aws.amazon.com/connect/latest/adminguide/flow-version-control.html), Sections View a previous version of a flow and Roll back a flow. Checked 2026-09-07.
