# Setting up Amazon Q in Connect for agent assist and self-service

Systems: Amazon Connect

For Amazon Connect administrators and contact centre engineers who already run an instance with flows and queues and are adding AWS's generative AI agent assist and, optionally, AI self-service.

Canonical: https://warmtransfer.net/guides/amazon-connect-q-setup

Last verified: 2026-10-01

In Amazon Connect, enabling AI agents (formerly Amazon Q in Connect) starts with creating a domain, also called an assistant, which the setup overview describes as consisting of a single knowledge base[^27]. For human agents, AI agents detect customer intent during calls, chats, tasks and emails and push generative responses with links to relevant articles, and AWS recommends agentic self-service rather than the legacy Self-service AI agent for new implementations[^10][^43].

## Before you start

AWS documentation states that Amazon Connect Customer is the current name for the product previously called Amazon Connect[^76]. All new Amazon Connect instances are Connect Customer instances[^54].

Creating an AI agent needs the AI agent designer - AI agents - Create permission[^57]. Creating an AI guardrail needs the AI guardrails - Create permission[^30].

AI agents account-level defaults are 5 assistants (not adjustable), 10 knowledge bases (adjustable) and 5,000 content items per knowledge base (adjustable), with adjustments requested through AWS Support[^58]. The default account-level quota for concurrent real-time calls with conversational analytics is 300, adjustable[^60].

Agent assist uses Amazon Bedrock cross-region inference and may process data in a Region other than the one selected, and customers who do not want that must contact AWS Support[^23]. AWS states that agent assist can be used in compliance with GDPR and is HIPAA eligible, and that AI agents are built on Amazon Bedrock with Bedrock automated abuse detection[^9].

Agentic self-service uses orchestrator AI agents that reason across multiple steps, invoke MCP tools and keep a continuous conversation until resolution or escalation, whereas legacy self-service returns control to the flow whenever a custom tool is selected[^5].

See also [Setting up an Amazon Connect instance](https://warmtransfer.net/knowledge/amazon-connect-instance-setup), [Amazon Connect contact flows and routing profiles](https://warmtransfer.net/knowledge/amazon-connect-flows) and [Amazon Lex bots in Amazon Connect](https://warmtransfer.net/knowledge/amazon-connect-lex-bots).

## What changes by situation

- Which plan is the instance on? Connect Customer; Customer Basic.
- Who owns the key that encrypts the AI agents domain? The default AWS owned key; A customer managed KMS key.
- Where do the answers come from? A prebuilt knowledge integration (S3, SharePoint Online, Salesforce, ServiceNow, Zendesk or web crawler); An existing Amazon Bedrock knowledge base.
- What should the AI do? Agent assist only; Agent assist plus agentic self-service; Agent assist plus legacy self-service.

## Step 1: Confirm the instance plan

**Connect Customer**

### Do
Open the Connect Customer pane on the instance's console page; an older instance is updated to Connect Customer by choosing **Enable** there[^54]. Connect Customer includes end-customer self-service via agentic voice and chat and real-time agent assistance among its AI capabilities[^19].
### Verify
Suggested check: confirm on the instance page that this plan shows as enabled before you continue.
### Rollback
Choosing **Disable** switches the instance from Connect Customer to Customer Basic, but it loses Connect Customer-only features and flows that use them may hit runtime errors[^67].

**Customer Basic**

### Do
Agentic voice, AI agent observability and AI agent performance evaluations are listed as available only in Connect Customer and not in Customer Basic[^6]. If you plan agentic voice self-service, update the instance by choosing **Enable** in the Connect Customer pane of the instance's console page[^54].
### Verify
Suggested check: confirm on the instance page which plan is active, and that it matches the self-service channels you intend to build.
### Rollback
If you chose **Enable**, choosing **Disable** switches the instance back to Customer Basic, but it loses Connect Customer-only features and flows that use them may hit runtime errors[^67].

## Step 2: Prepare the encryption key

**The default AWS owned key**

### Do
Create no key: by default an AI agents domain and its connection are encrypted with an AWS owned key[^24]. Search indices are always encrypted at rest with an AWS owned key[^72].
### Verify
Suggested check: when you create the domain in Step 3, leave the encryption settings at their default.

**A customer managed KMS key**

### Do
Create or choose a customer managed KMS key for the domain, which encrypts the excerpts shown in agent recommendations, and optionally a second key for content imported from S3, SharePoint Online, Salesforce, ServiceNow or Zendesk[^72]. Using a customer managed KMS key is optional and incurs AWS KMS charges[^24]. To use AI agents with chat, task and email contacts, the domain key policy must grant the `connect.amazonaws.com` service principal `kms:Decrypt`, `kms:GenerateDataKey*` and `kms:DescribeKey`[^41]. A Lex V2 bot that uses a custom IAM role needs KMS permissions added manually when a customer managed key is used[^45].
### Verify
Search indices remain encrypted at rest with an AWS owned key even when you supply your own keys[^72]. Suggested check: read back the key policy and confirm the service principal statement lists all three actions.
### Rollback
Suggested rollback: remove the added policy statement, and retire a key created only for this purpose, once nothing uses it.

## Step 3: Create the AI agents domain and attach the instance

### Do
On the instance, create the AI agents domain, also called an assistant, applying your encryption choice[^27][^24]. A domain can be associated with one or more Amazon Connect instances, but an instance can be associated with only one domain[^36]. Separate domains do not share external application integrations or customer data with each other[^28]. Every Amazon Connect instance associated with a domain inherits that domain's knowledge integrations[^37]. We infer that trialling a different knowledge configuration without affecting production agents means using a separate non-production instance associated with a separate domain[^70]. Record the domain's full ARN, because the Connect assistant block's Config tab takes it[^18].

### Verify
Suggested check: confirm the domain is listed for the instance and that you have recorded its full identifier.

### Rollback
An Amazon Connect instance can be associated with a different AI agents domain at any time by choosing a different domain[^26].

## Step 4: Add the knowledge integration

**A prebuilt knowledge integration (S3, SharePoint Online, Salesforce, ServiceNow, Zendesk or web crawler)**

### Do
In the Amazon Connect console, add a prebuilt knowledge integration for Amazon S3, Microsoft SharePoint Online, Salesforce, ServiceNow, Zendesk or the web crawler[^51]. Knowledge integrations are created at the domain level[^37].

- A ServiceNow integration requires versioning to be enabled on the ServiceNow knowledge base articles, or it fails to create[^64].
- A SharePoint Online integration supports only the AUTHORIZATION_CODE connection type, not CLIENT_CREDENTIALS, and allows at most 10 folders[^66].
- The web crawler follows robots.txt, does not crawl JavaScript dynamically generated pages, accepts a seed URL plus up to 9 additional source URLs, and stops a crawl after a default 1-hour timeout[^74].
- For Salesforce, ServiceNow and Zendesk, the sync frequency defaults to 1 hour, and all records are ingested unless an ingestion start date is set[^68].

### Verify
Suggested check: confirm the new integration appears in the domain's integration list.
### Rollback
Suggested rollback: remove the integration from the domain. AI agents knowledge bases do not process deletions in Salesforce or ServiceNow or hard deletes and archives in Zendesk, so articles must be archived in Salesforce, retired in ServiceNow or unpublished in Zendesk to leave the knowledge base[^25].

**An existing Amazon Bedrock knowledge base**

### Do
In the Amazon Connect console, choose the option to bring an existing Amazon Bedrock knowledge base[^51]. This integration is compatible only with orchestration AI agent types[^16]. It is available only for on-contact use and does not support off-contact manual search[^15].
### Verify
Suggested check: confirm the existing knowledge base now appears as an integration on the domain.
### Rollback
Suggested rollback: remove the integration from the domain, leaving the existing knowledge base itself in place.

## Step 5: Confirm content has been ingested

### Do
Call the `GetKnowledgeBase` API and read the `lastContentModificationTime` field, which shows the last time the knowledge base's available content changed[^40]. The default quota is 5,000 content items per knowledge base, adjustable through AWS Support[^58].

### Verify
Suggested check: confirm the timestamp is later than the time you added the integration or made your most recent expected content change.

## Step 6: Choose the AI agent that serves human agents

**A prebuilt knowledge integration (S3, SharePoint Online, Salesforce, ServiceNow, Zendesk or web crawler)**

### Do
Amazon Connect ships system AI agents including Orchestration, Answer Recommendation, Manual Search, Self Service and Agent Assistance, and each use case uses its default system AI agent unless a customised one overrides it[^69]. To customise, create an AI agent that specifies one or more customised AI prompt versions and one AI guardrail; prompts you do not override keep using the system default[^7]. Publish the agent, which creates an immutable version, because only a published version can be selected as a default[^57].
### Verify
AI agent versions set on an agent assist session take precedence over those set on the assistant, which take precedence over system defaults, and an assistant-level change applies from the next contact and session created[^1]. Suggested check: confirm the published version is selectable as the default for its use case.
### Rollback
Revert customisation by listing system AI agent versions with `aws qconnect list-ai-agents --origin SYSTEM` and setting them back on the assistant or session[^61].

**An existing Amazon Bedrock knowledge base**

### Do
Use an AI agent of the Orchestration type, because the Amazon Bedrock knowledge base integration is compatible only with orchestration AI agent types[^16]. The Connect assistant block's Config tab takes the Orchestration AI agent to use for Agent Assistance, so you select this agent there when you add the block to the flow[^18]. Orchestration AI agents show customers only the parts of a model response wrapped in `<message>` tags, so a custom orchestration prompt must keep that formatting instruction[^53]. Orchestration AI agents require chat streaming to be enabled for chat contacts; without it some messages fail to render[^55]. Publish the agent, because only a published version can be selected as a default[^57].
### Verify
An assistant-level change applies from the next contact and session created[^1]. Suggested check: confirm the published orchestration agent is selectable in the flow block configuration.
### Rollback
Revert customisation by listing system AI agent versions with `aws qconnect list-ai-agents --origin SYSTEM` and setting them back on the assistant or session[^61].

## Step 7: Create and attach an AI guardrail

### Do
In the Connect admin website, go to AI agent designer, then AI guardrails, where AI guardrails for Amazon Connect AI agents are created and edited as Amazon Bedrock guardrails[^30]. The builder offers content filters, denied topics (up to 30), contextual grounding check, word filters, sensitive information filters for PII and custom regex, and blocked messaging; image content filters are not supported[^34]. Do not add a contextual grounding policy to a guardrail that an orchestration AI agent will use, because attaching one causes a validation error[^33]. A guardrail is saved as Latest:Draft and must be published, which creates a new guardrail version[^35]. Attach the guardrail to your customised AI agent, which can carry one AI guardrail[^7]. A deployment can have up to 3 custom AI guardrails, and creating a fourth returns an error[^32].

### Verify
Guardrails on streaming responses add latency, mainly to time-to-first-token, and AWS advises benchmarking guardrail configurations against the use case[^31]. Suggested check: confirm the guardrail shows a published version rather than only a draft.

### Rollback
Suggested rollback: detach the guardrail from the AI agent, publish a new agent version, and delete the guardrail if it is no longer needed.

## Step 8: Add agent assist to the contact flows

### Do
Add a Connect assistant block to the flow; it associates the AI agents domain and the default AI agent mapping with the current contact[^12]. The block supports voice, chat, task and email, can be used in Inbound, Customer Queue, Outbound whisper, Transfer to Agent and Transfer to Queue flows, and has Success and Error branches[^17]. On its Config tab, enter the full ARN of the AI agents domain and, if you use one, the Orchestration AI agent for Agent Assistance[^18]. Sending an outbound email to the block does nothing but is still charged, so AWS advises a Check contact attributes block before it to route tasks and outbound emails around it[^56].

For calls, the flow must also contain a Set recording and analytics behavior block configured for real-time conversational analytics; its position in the flow does not matter, and chats do not need conversational analytics[^73]. For new flows or modifications, that block is replaced by Set recording, analytics and processing behavior, while the earlier block stays supported in existing flows[^65]. Both agent and customer call recordings are required to use conversational analytics for voice contacts[^77]. Analytics settings are overwritten by each subsequent Set recording and analytics behavior block in a flow[^78]. A transfer to another agent or queue creates a second contact ID, so add another recording block with analytics enabled for conversational analytics to continue on the transferred contact[^71].

Save stores a draft of the flow and Publish activates it immediately, and every connector must be attached to a block before a flow can be published[^79].

### Verify
The Connect assistant block exits through either its Success or its Error branch[^17]. Suggested check: place a test call and a test chat and confirm the block takes its Success branch on each.

### Rollback
Previously published versions of a flow are available through the Latest: Published dropdown, and a rollback is performed by opening a previous version and choosing Publish[^80].

## Step 9: Give agents access

### Do
Add the Agent Applications permission Connect assistant - Access to the agents' security profiles, which lets them search and view content and receive automatic recommendations on calls when conversational analytics is enabled; the Admin profile has all Connect assistant permissions by default[^11]. Agents using the AWS-provided CCP reach the assistant at `https://instance-name.my.connect.aws/agent-app-v2/` or the awsapps.com/connect/agent-app-v2/ form, and an embedded CCP must initialise the assistant through Amazon Connect Streams[^75].

### Verify
At that URL the CCP and the assistant show in one window[^75]. Suggested check: sign in as a test agent and confirm the assistant appears next to the contact controls.

### Rollback
Suggested rollback: remove the access permission from the agents' security profiles.

## Step 10: Build self-service

**Agent assist only**

### Do
For agent assist alone, the flow change is the Connect assistant block added to the contact flows, which associates the AI agents domain and the default AI agent mapping with the current contact[^12].
### Verify
Suggested check: confirm that no customer-facing bot or self-service agent was added to the entry flow.

**Agent assist plus agentic self-service**

### Do
In AI agent designer, create an AI agent of type Orchestration copied from the SelfServiceOrchestrator system agent, then assign it a security profile and tools[^3]. Orchestration AI agents use the same security profile framework as human agents and can execute only the tools their assigned security profile explicitly permits[^8]. The SelfServiceOrchestrator includes default Complete and Escalate Return to Control tools[^29]. Constant tools return a configured static string to the orchestrator without ending the conversation, which AWS positions for testing before connecting real backends through MCP tools[^21]. Keep the `<message>` formatting instruction in any custom prompt, because orchestration agents show customers only text wrapped in those tags[^53]. Publish the agent and set it as default in the Self Service row of Default AI Agent Configurations on the AI Agents page; the SelfServiceOrchestration prompt is usable as-is[^4].

Next, create a Conversational AI bot with the Connect AI agent intent enabled, and a flow whose Get customer input block invokes that bot[^2]. After the Default output of Get customer input, add a Check contact attributes block reading Namespace Lex, Key Session attributes, Session Attribute Key `Tool`, where the Return to Control tool name and inputs are stored once the AI conversation ends[^62]. Following AWS's example, route Complete to Disconnect, Escalate to Set working queue and Transfer to queue, and No match to Disconnect or other logic[^29]. On chat contacts, enable chat streaming, which orchestration AI agents require[^55].
### Verify
If the customer sees no AI messages, check the prompt, because a custom orchestration prompt that omits the `<message>` instruction produces no visible messages[^53]. Suggested check: as a test customer, complete one task through a test tool, then separately ask for a person, and confirm the first ends the contact and the second reaches the queue. Suggested check: confirm the agent who takes the escalated contact receives recommendations.
### Rollback
Revert the self-service agent by listing system AI agent versions with `aws qconnect list-ai-agents --origin SYSTEM` and setting them back[^61]. To restore the previous entry flow, open its earlier version from the Latest: Published dropdown and choose Publish[^80].

**Agent assist plus legacy self-service**

### Do
AWS labels this self-service build legacy, says it is not receiving new feature updates, and recommends agentic self-service for new implementations[^43]. Keep the system Self Service AI agent, or override it with a customised one, which is the default unless overridden[^69]. Publish any customised agent, because only a published version can be selected as a default[^57].

Enable `AMAZON.QinConnectIntent` in the Lex bot, add a Connect assistant block, and add a Get customer input block that invokes the bot, optionally followed by a Check contact attributes block on the Lex session attribute `Tool`[^44]. The agent assist intent toggle on a bot's Configuration tab works only for bots created in the Amazon Connect admin website; bots created elsewhere must be updated in the Amazon Lex console[^39]. The Connect assistant step must run before the bot, because the AI agents session ARN must be created and passed from the instance[^49]. Legacy self-service ships default tools QUESTION, ESCALATION, CONVERSATION, COMPLETE and FOLLOW_UP_QUESTION, and when ESCALATION is selected the contact takes the Error branch of the Get customer input block, so wire that branch to a queue[^42].

`AMAZON.QinConnectIntent` is activated when an utterance is not classified into any other intent, but not for missed utterances while a slot value is being elicited[^46]. It cannot share a bot locale with intents that have no specific utterances such as `AMAZON.QnAIntent` or `AMAZON.BedrockAgentIntent`[^38]. A bot locale can hold at most one `AMAZON.QinConnectIntent`, and the AI agents domain must be in the same AWS Region as the Lex V2 bot[^47]. A bot on its service-linked role gets the AI agents session and assistant permissions automatically, while a bot on a custom IAM role needs them added manually[^45].
### Verify
The intent returns the session attribute `x-amz-lex:q-in-connect:conversation-status` (CLOSED, READY or PROCESSING) and a status reason of SUCCESS, FAILED or REJECTED, where REJECTED recommends handling outside the bot[^50]. Suggested check: ask one question the knowledge base covers, one it does not, and one request for a person, and confirm an answer, a failed or rejected status, and a queue transfer respectively.
### Rollback
Suggested rollback: turn the intent off on the bot. To restore the previous flow, open its earlier version from the Latest: Published dropdown and choose Publish[^80]. Revert a customised agent by listing system AI agent versions with `aws qconnect list-ai-agents --origin SYSTEM` and setting them back[^61].

## Step 11: Test agent assist end to end

**A prebuilt knowledge integration (S3, SharePoint Online, Salesforce, ServiceNow, Zendesk or web crawler)**

### Do
Place a test call and a test chat that raise an issue your knowledge base covers; AI agents detect customer intent during calls, chats, tasks and emails and push generative responses with links to relevant articles[^10]. As the agent, also search in natural language during the contact, during After Contact Work and between contacts[^52]. Ask something your guardrail should block; the default blocked input message is "Blocked input text by guardrail."[^35]
### Verify
Search results clear after Close contact or the search Close icon[^52]. Suggested check: confirm recommendations with article links appeared on both test contacts and that the blocked request returned your blocked message.

**An existing Amazon Bedrock knowledge base**

### Do
Place a test call and a test chat that raise an issue your knowledge base covers; AI agents detect customer intent during calls, chats, tasks and emails and push generative responses with links to relevant articles[^10]. Test search only while on a contact, because the Amazon Bedrock knowledge base integration does not support off-contact manual search[^15]. Ask something your guardrail should block; the default blocked input message is "Blocked input text by guardrail."[^35]
### Verify
Without chat streaming enabled, some orchestration agent messages fail to render on chat contacts[^55]. Suggested check: confirm recommendations with article links appeared on both test contacts and that the blocked request returned your blocked message.

## Applicability

Applies to: Amazon Web Services Amazon Connect, Amazon Web Services Amazon Lex, and Amazon Web Services Amazon Connect Customer. Deployments: multi-tenant. Sources checked 2026-10-01. Agentic voice is listed as available only in Connect Customer and not in Customer Basic[^6]. The legacy self-service intent documentation applies to Lex V2 bots[^45]. Agent assist may process data in a Region other than the one selected through Amazon Bedrock cross-region inference[^23].

## What remains uncertain

Per-minute and per-message prices for either plan, and how AI usage is billed on each, are not covered by the sources below. The maximum file size for documents ingested through file-based integrations is not covered by the sources below. Which languages the legacy Self-service AI agent supports is not covered by the sources below. Whether Customer Basic instances can use orchestration AI agents for agent assist or for agentic chat self-service is not covered by the sources below. What happens to contacts already in progress when an instance is associated with a different domain is not covered by the sources below. Setting up MCP tool namespaces and their backend authentication is not covered by the sources below.

## Sources

[^1]: AI agent versions set on an agent assist session take precedence over those set on the assistant, which take precedence over system defaults; an assistant-level change applies from the next contact and session created. Source: [Create AI agents in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-agents.html), Sample CLI commands > Set AI agents for use with agent assist (both sub-sections). Checked 2026-10-01.
[^2]: Agentic self-service then needs a Conversational AI bot with the Connect AI agent intent enabled and a flow whose Get customer input block invokes that bot, followed by a Check contact attributes block that routes on the Return to Control tool chosen. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Set up agentic self-service, steps 6-7. Checked 2026-10-01.
[^3]: Agentic self-service setup starts by creating an AI agent of type Orchestration in AI agent designer, copied from the SelfServiceOrchestrator system agent, then assigning it a security profile and tools. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Set up agentic self-service, steps 1-3. Checked 2026-10-01.
[^4]: For agentic self-service the published orchestrator AI agent is set as default in the Self Service row of Default AI Agent Configurations on the AI Agents page, with the SelfServiceOrchestration prompt usable as-is. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Set up agentic self-service, steps 4-5. Checked 2026-10-01.
[^5]: Agentic self-service uses orchestrator AI agents that reason across multiple steps, invoke MCP tools and keep a continuous conversation until resolution or escalation, whereas legacy self-service returns control to the flow whenever a custom tool is selected. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Opening paragraph. Checked 2026-10-01.
[^6]: Agentic voice, AI agent observability and AI agent performance evaluations are listed as available only in Connect Customer and not in Customer Basic. Source: [Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/enable-nextgeneration-amazonconnect.html), Features only available in Connect Customer. Checked 2026-10-01.
[^7]: A customised AI agent can specify one or more customised AI prompt versions and one AI guardrail; prompts not overridden keep using the system default. Source: [Create AI agents in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-agents.html), Here's how customized AI agents work bullets; How to create AI agents step 6 Note. Checked 2026-10-01.
[^8]: Orchestration AI agents use the same security profile framework as human agents, and an AI agent can execute only the tools its assigned security profile explicitly permits. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Key capabilities, Security profiles bullet. Checked 2026-10-01.
[^9]: AWS states that agent assist can be used in compliance with GDPR and is HIPAA eligible, and that AI agents are built on Amazon Bedrock with Bedrock automated abuse detection. Source: [Use AI agents for real-time assistance](https://docs.aws.amazon.com/connect/latest/adminguide/connect-ai-agent.html), Powered by Amazon Bedrock banner; final paragraph. Checked 2026-10-01.
[^10]: For human agents, AI agents detect customer intent during calls, chats, tasks and emails using conversational analytics and natural language understanding and push generative responses with links to relevant articles; agents can also query directly in natural language. Source: [Use AI agents for real-time assistance](https://docs.aws.amazon.com/connect/latest/adminguide/connect-ai-agent.html), Third and fourth paragraphs. Checked 2026-10-01.
[^11]: Agents need the Agent Applications security profile permission Connect assistant - Access to search and view content and to receive automatic recommendations on calls when conversational analytics is enabled; the Admin profile has all Connect assistant permissions by default. Source: [Access Connect assistant in the Connect agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/access-connect-assistant-in-workspace.html), Security profile permissions for the Connect assistant. Checked 2026-10-01.
[^12]: To enable out-of-the-box agent assist on contacts, add a Connect assistant block to the flow; it associates the AI agents domain and the default AI agent mapping with the current contact. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Step 4: Configure your flow for agent assist, item 1. Checked 2026-10-01.
[^13]: Under Customer Basic, AI agent assistance and AI self-service are each listed at $0.0080 per voice minute and $0.0015 per chat message on top of channel charges. Source: [Amazon Connect Customer Pricing Appendix](https://aws.amazon.com/products/connect/customer/pricing/appendix/), Customer Basic pricing, AI agents rows (self-service and agent assistance). Checked 2026-10-01.
[^14]: The Customer Basic pricing appendix lists voice channel usage at $0.018 per minute and chat at $0.004 per message, with AI features billed separately. Source: [Amazon Connect Customer Pricing Appendix](https://aws.amazon.com/products/connect/customer/pricing/appendix/), Customer Basic pricing, voice and chat channel rows. Checked 2026-10-01.
[^15]: The Amazon Bedrock knowledge base integration is available only for on-contact use and does not support off-contact manual search. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Step 3 > Create a Bedrock knowledge base integration, second Note. Checked 2026-10-01.
[^16]: The bring-your-own Amazon Bedrock knowledge base integration is compatible only with orchestration AI agent types. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Step 3 > Create a Bedrock knowledge base integration, first Note. Checked 2026-10-01.
[^17]: The Connect assistant block supports voice, chat, task and email, can be used in Inbound, Customer Queue, Outbound whisper, Transfer to Agent and Transfer to Queue flows, and has Success and Error branches. Source: [Flow block in Connect Customer: Connect assistant](https://docs.aws.amazon.com/connect/latest/adminguide/connect-assistant-block.html), Supported channels table; Flow types; Configured block. Checked 2026-10-01.
[^18]: The Connect assistant block's Config tab takes the full ARN of the AI agents domain and the Orchestration AI agent to use for Agent Assistance. Source: [Flow block in Connect Customer: Connect assistant](https://docs.aws.amazon.com/connect/latest/adminguide/connect-assistant-block.html), How to configure this block. Checked 2026-10-01.
[^19]: Connect Customer includes end-customer self-service via agentic voice and chat and real-time agent assistance among its AI capabilities. Source: [Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/enable-nextgeneration-amazonconnect.html), AI capabilities list. Checked 2026-10-01.
[^20]: The Connect Customer pricing page lists voice at $0.038 per minute and chat at $0.010 per message, plus standard telephony rates, with no separate token or seat charge for AI features. Source: [Amazon Connect Customer Pricing](https://aws.amazon.com/connect/pricing/), Pricing section, channel rates. Checked 2026-10-01.
[^21]: Constant tools return a configured static string to the orchestrator AI agent without ending the conversation, which AWS positions for testing before connecting real backends through MCP tools. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Use Constant tools for testing and development. Checked 2026-10-01.
[^22]: The AI agents setup page says ingestion supports HTML, Word (DOCX only), PDF and UTF-8 text files up to 1 MB, and PDFs must not be encrypted or password protected (disputed). Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Supported content types. Checked 2026-10-01.
[^23]: Agent assist uses Amazon Bedrock cross-region inference and may process data in a Region other than the one selected; customers who do not want that must contact AWS Support. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Cross-region inference service. Checked 2026-10-01.
[^24]: By default an AI agents domain and its connection are encrypted with an AWS owned key; using a customer managed KMS key is optional and incurs AWS KMS charges. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin > (Optional) Create AWS KMS keys to encrypt the domain and the content. Checked 2026-10-01.
[^25]: AI agents knowledge bases do not process deletions in Salesforce or ServiceNow or hard deletes and archives in Zendesk; articles must be archived in Salesforce, retired in ServiceNow or unpublished in Zendesk to leave the knowledge base. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Note list at end of Step 3, first two bullets. Checked 2026-10-01.
[^26]: An Amazon Connect instance can be associated with a different AI agents domain at any time by choosing a different domain. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin, last guideline bullet. Checked 2026-10-01.
[^27]: In Amazon Connect, enabling AI agents (formerly Amazon Q in Connect) starts with creating a domain, also called an assistant, which the setup overview describes as consisting of a single knowledge base. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Integration overview, item 1; Before you begin, first paragraph. Checked 2026-10-01.
[^28]: Separate AI agents domains do not share external application integrations or customer data with each other. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin, first guideline bullet. Checked 2026-10-01.
[^29]: The SelfServiceOrchestrator includes default Complete and Escalate Return to Control tools; AWS's example routes Complete to Disconnect, Escalate to Set working queue and Transfer to queue, and No match to Disconnect or other logic. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Tools for orchestrator AI agents, Return to Control bullet; Configure routing based on Return to Control tools steps 4-5. Checked 2026-10-01.
[^30]: AI guardrails for Amazon Connect AI agents are Amazon Bedrock guardrails created and edited in the Connect admin website under AI agent designer, AI guardrails, with the AI guardrails - Create permission. Source: [Create AI guardrails for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-guardrails.html), Opening paragraph; How to create an AI guardrail steps 1-2. Checked 2026-10-01.
[^31]: Guardrails on streaming responses add latency, mainly to time-to-first-token, because text must be buffered and scanned before delivery, and AWS advises benchmarking guardrail configurations against the use case. Source: [Create AI guardrails for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-guardrails.html), Important things to know, fourth and fifth bullets. Checked 2026-10-01.
[^32]: An Amazon Connect AI agents deployment can have up to three custom AI guardrails; creating a fourth returns an error. Source: [Create AI guardrails for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-guardrails.html), Important things to know, first bullet; Change the default blocked message, step 4. Checked 2026-10-01.
[^33]: Orchestration AI agents do not support contextual grounding policies; attaching a guardrail with a contextual grounding policy to an orchestration AI agent causes a validation error. Source: [Create AI guardrails for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-guardrails.html), Important things to know, second bullet. Checked 2026-10-01.
[^34]: The AI Guardrail builder offers content filters, denied topics (up to 30), contextual grounding check, word filters, sensitive information filters for PII and custom regex, and blocked messaging; image content filters are not supported. Source: [Create AI guardrails for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-guardrails.html), How to create an AI guardrail, step 5. Checked 2026-10-01.
[^35]: A guardrail is saved as Latest:Draft and must be published, which creates a new guardrail version, and the default blocked input message shown to users is 'Blocked input text by guardrail.'. Source: [Create AI guardrails for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-guardrails.html), How to create an AI guardrail, steps 6-7; Change the default blocked message, first paragraph. Checked 2026-10-01.
[^36]: An AI agents domain can be associated with one or more Amazon Connect instances, but an instance can be associated with only one domain. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin, guideline bullets. Checked 2026-10-01.
[^37]: Knowledge integrations are created at the domain level, and every Amazon Connect instance associated with a domain inherits that domain's integrations. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin, Note under guideline bullets. Checked 2026-10-01.
[^38]: AMAZON.QinConnectIntent cannot share a bot locale with intents that have no specific utterances such as AMAZON.QnAIntent or AMAZON.BedrockAgentIntent. Source: [AMAZON.QinConnectIntent](https://docs.aws.amazon.com/lexv2/latest/dg/built-in-intent-qinconnect.html), Limitations, first bullet. Checked 2026-10-01.
[^39]: The agent assist intent toggle on a bot's Configuration tab works only for bots created in the Amazon Connect admin website; bots created elsewhere must be updated in the Amazon Lex console. Source: [Create an agent assist intent from a Connect Customer instance](https://docs.aws.amazon.com/connect/latest/adminguide/create-qic-intent-connect.html), Procedure steps 2-3 and note under step 3. Checked 2026-10-01.
[^40]: The last time a knowledge base's available content changed can be confirmed from the lastContentModificationTime field returned by the GetKnowledgeBase API. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), When was your knowledge base last updated?. Checked 2026-10-01.
[^41]: To use AI agents with chat, task and email contacts, the domain's customer managed key policy must grant the connect.amazonaws.com service principal kms:Decrypt, kms:GenerateDataKey* and kms:DescribeKey. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin, Note; Step 2: Encrypt the domain > Use an existing key, Note. Checked 2026-10-01.
[^42]: Legacy self-service ships default tools QUESTION, ESCALATION, CONVERSATION, COMPLETE and FOLLOW_UP_QUESTION, and when ESCALATION is selected the contact takes the Error branch of the Get customer input block. Source: [(legacy) Use generative AI-powered self-service with AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/generative-ai-powered-self-service.html), Default system tools, items 1-5 and Note under ESCALATION. Checked 2026-10-01.
[^43]: AWS labels the generative AI-powered self-service built on the Self-service AI agent as legacy, says it is not receiving new feature updates, and recommends agentic self-service for new implementations. Source: [(legacy) Use generative AI-powered self-service with AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/generative-ai-powered-self-service.html), Page title and Important banner. Checked 2026-10-01.
[^44]: Legacy self-service is set up by enabling AMAZON.QinConnectIntent in the Lex bot, adding a Connect assistant block, and adding a Get customer input block that invokes the bot, optionally followed by a Check contact attributes block on the Lex session attribute Tool. Source: [(legacy) Use generative AI-powered self-service with AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/generative-ai-powered-self-service.html), Set up self-service, steps 1-5. Checked 2026-10-01.
[^45]: If the Lex V2 bot uses its service-linked role, Lex adds the AI agents session and assistant permissions automatically; a bot using a custom IAM role needs them added manually, plus KMS permissions when a customer managed key is used. Source: [AMAZON.QinConnectIntent](https://docs.aws.amazon.com/lexv2/latest/dg/built-in-intent-qinconnect.html), Permissions section and Note. Checked 2026-10-01.
[^46]: AMAZON.QinConnectIntent is activated when an utterance is not classified into any other intent in the bot, but not for missed utterances while a slot value is being elicited. Source: [AMAZON.QinConnectIntent](https://docs.aws.amazon.com/lexv2/latest/dg/built-in-intent-qinconnect.html), Intent description paragraph. Checked 2026-10-01.
[^47]: A bot locale can hold at most one AMAZON.QinConnectIntent, and the AI agents domain it uses must be in the same AWS Region as the Lex V2 bot. Source: [AMAZON.QinConnectIntent](https://docs.aws.amazon.com/lexv2/latest/dg/built-in-intent-qinconnect.html), Limitations, third and fourth bullets. Checked 2026-10-01.
[^48]: The Lex V2 AMAZON.QinConnectIntent page says that if a language other than U.S. English is selected, the SELF_SERVICE_PRE_PROCESSING and SELF_SERVICE_ANSWER_GENERATION prompts must be customised to respond in that language (disputed). Source: [AMAZON.QinConnectIntent](https://docs.aws.amazon.com/lexv2/latest/dg/built-in-intent-qinconnect.html), Second Note, second bullet. Checked 2026-10-01.
[^49]: When a bot with AMAZON.QinConnectIntent runs on an Amazon Connect contact, the AI agents session ARN must be created and passed from the instance, which the Lex page says a flow does with the Amazon Q in Connect (Connect assistant) step. Source: [AMAZON.QinConnectIntent](https://docs.aws.amazon.com/lexv2/latest/dg/built-in-intent-qinconnect.html), Limitations, second bullet; Note after session attributes. Checked 2026-10-01.
[^50]: AMAZON.QinConnectIntent returns session attributes including x-amz-lex:q-in-connect:conversation-status (CLOSED, READY or PROCESSING) and a status reason of SUCCESS, FAILED or REJECTED, where REJECTED recommends handling outside the bot. Source: [AMAZON.QinConnectIntent](https://docs.aws.amazon.com/lexv2/latest/dg/built-in-intent-qinconnect.html), Session Attributes Returned from QinConnectIntent, items 2-3. Checked 2026-10-01.
[^51]: The Amazon Connect console offers prebuilt knowledge integrations for Amazon S3, Microsoft SharePoint Online, Salesforce, ServiceNow, Zendesk and a web crawler, plus an option to bring an existing Amazon Bedrock knowledge base. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Integration overview item 3; Step 3: Create an integration (knowledge base) sub-sections. Checked 2026-10-01.
[^52]: Agents can search connected knowledge in natural language at any time: while on a contact, during After Contact Work or between contacts, and results clear after Close contact or the search Close icon. Source: [Search for content using Connect Customer agent assist](https://docs.aws.amazon.com/connect/latest/adminguide/search-for-answers.html), Third paragraph; To search for content, step 4. Checked 2026-10-01.
[^53]: Orchestration AI agents show customers only the parts of a model response wrapped in <message> tags, so a custom orchestration prompt that omits this formatting instruction produces no visible messages. Source: [How to use orchestrator AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/use-orchestration-ai-agent.html), Message parsing, first paragraph. Checked 2026-10-01.
[^54]: All new Amazon Connect instances are Connect Customer instances, and an older instance can be updated by choosing Enable in the Connect Customer pane of the instance's console page. Source: [Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/enable-nextgeneration-amazonconnect.html), Updating an existing instance to Connect Customer. Checked 2026-10-01.
[^55]: Orchestration AI agents require chat streaming to be enabled for chat contacts; without it some messages fail to render. Source: [How to use orchestrator AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/use-orchestration-ai-agent.html), Note after tool and security profile bullets. Checked 2026-10-01.
[^56]: Sending an outbound email to the Connect assistant block does nothing but is still charged, so AWS advises a Check contact attributes block before it to route tasks and outbound emails around it. Source: [Flow block in Connect Customer: Connect assistant](https://docs.aws.amazon.com/connect/latest/adminguide/connect-assistant-block.html), Supported channels, Note. Checked 2026-10-01.
[^57]: An AI agent must be published (Publish creates an immutable version) before that version can be selected as a default; creating one needs the AI agent designer - AI agents - Create permission. Source: [Create AI agents in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-agents.html), How to create AI agents, steps 1 and 8; Create AI agent versions. Checked 2026-10-01.
[^58]: AI agents account-level default quotas are 5 assistants (not adjustable), 10 knowledge bases (adjustable) and 5,000 content items per knowledge base (adjustable), with adjustments requested through AWS Support. Source: [Connect Customer service quotas](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-service-limits.html), Connect Customer AI agents service quotas table and Note. Checked 2026-10-01.
[^59]: The Amazon Connect service quotas page lists the AI agents maximum size per document as 5MB, adjustable (disputed). Source: [Connect Customer service quotas](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-service-limits.html), Connect Customer AI agents service quotas table, row Maximum size per document. Checked 2026-10-01.
[^60]: The default account-level quota for concurrent real-time calls with conversational analytics is 300, adjustable. Source: [Connect Customer service quotas](https://docs.aws.amazon.com/connect/latest/adminguide/amazon-connect-service-limits.html), Conversational analytics service quotas table, row Concurrent real-time calls with analytics. Checked 2026-10-01.
[^61]: Customisation can be reverted by listing system AI agent versions with aws qconnect list-ai-agents --origin SYSTEM and setting them back on the assistant or session. Source: [Create AI agents in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-agents.html), Sample CLI commands > Revert to system defaults. Checked 2026-10-01.
[^62]: When an orchestrator AI agent invokes a Return to Control tool the AI conversation ends, control returns to the flow, and the tool name and inputs are stored as Lex session attributes read with Namespace Lex, Key Session attributes, Session Attribute Key Tool after the Default output of Get customer input. Source: [Use agentic self-service](https://docs.aws.amazon.com/connect/latest/adminguide/agentic-self-service.html), Handle Return to Control tools in your contact flow > How Return to Control detection works; Configure routing based on Return to Control tools steps 1-2. Checked 2026-10-01.
[^63]: The AI agent designer page says the locale cannot be chosen for the Self-service AI agent type and only English is supported (disputed). Source: [Create AI agents in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-agents.html), How to create AI agents, step 5. Checked 2026-10-01.
[^64]: A ServiceNow knowledge integration requires versioning to be enabled on the ServiceNow knowledge base articles; without it the integration fails to create. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Step 3 > Create a ServiceNow integration, Important note in step 1. Checked 2026-10-01.
[^65]: The Set recording and analytics behavior block stays supported in existing flows but is replaced by Set recording, analytics and processing behavior for new flows or modifications. Source: [Flow block in Connect Customer: Set recording and analytics behavior](https://docs.aws.amazon.com/connect/latest/adminguide/set-recording-behavior.html), Top-of-page Note. Checked 2026-10-01.
[^66]: A SharePoint Online knowledge integration supports only the AUTHORIZATION_CODE connection type, not CLIENT_CREDENTIALS, and allows at most 10 folders. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Step 3 > Create a SharePoint Online integration, Note; closing Note list after Bedrock section. Checked 2026-10-01.
[^67]: An instance can be switched from Connect Customer to Customer Basic with Disable, but it loses Connect Customer-only features and flows that use them may hit runtime errors. Source: [Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/enable-nextgeneration-amazonconnect.html), How to switch to Customer Basic, paragraph and Warning. Checked 2026-10-01.
[^68]: For Salesforce, ServiceNow and Zendesk integrations the sync frequency is optional and defaults to one hour, and by default all records are ingested unless an ingestion start date is set. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Step 3 > Create a Salesforce integration step 1; Create a ServiceNow integration; Create a Zendesk integration. Checked 2026-10-01.
[^69]: Amazon Connect ships system AI agents including Orchestration, Answer Recommendation, Manual Search, Self Service and Agent Assistance, and each use case uses a default system AI agent unless a customised one overrides it. Source: [Create AI agents in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/create-ai-agents.html), Opening system AI agent list and following paragraph. Checked 2026-10-01.
[^70]: Because an instance can hold only one domain and every associated instance inherits the domain's integrations, trialling a different knowledge configuration without affecting production agents implies using a separate non-production instance associated with a separate domain (inferred). Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin, guideline bullets and Note (reasoned from the one-domain-per-instance and inheritance rules). Checked 2026-10-01.
[^71]: A transfer to another agent or queue creates a second contact ID, so another Set recording behavior block with analytics enabled is needed for conversational analytics to continue on the transferred contact. Source: [Flow block in Connect Customer: Set recording and analytics behavior](https://docs.aws.amazon.com/connect/latest/adminguide/set-recording-behavior.html), Configuration tips, transfer bullet. Checked 2026-10-01.
[^72]: Customers managing their own keys can supply two KMS keys: one for the domain, which encrypts the excerpts shown in agent recommendations, and one for content imported from S3, SharePoint Online, Salesforce, ServiceNow or Zendesk; search indices are always encrypted at rest with an AWS owned key. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Before you begin > (Optional) Create AWS KMS keys to encrypt the domain and the content, bullets. Checked 2026-10-01.
[^73]: To use AI agents on calls, the flow must also contain a Set recording and analytics behavior block configured for real-time conversational analytics; its position in the flow does not matter, and chats do not need conversational analytics. Source: [Flow block in Connect Customer: Connect assistant](https://docs.aws.amazon.com/connect/latest/adminguide/connect-assistant-block.html), Configuration tips, both bullets. Checked 2026-10-01.
[^74]: The AI agents web crawler integration follows robots.txt, does not crawl JavaScript dynamically generated pages, accepts a seed URL plus up to 9 additional source URLs, and stops a crawl after a default one-hour timeout. Source: [Initial set-up for AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/enable-q.html), Step 3 > Create a web crawler integration > Prerequisites and Connection configuration step 3. Checked 2026-10-01.
[^75]: Agents using the AWS-provided CCP reach the Connect assistant at https://instance-name.my.connect.aws/agent-app-v2/ (or the awsapps.com/connect/agent-app-v2/ form), which shows the CCP and assistant in one window; an embedded CCP must initialise the assistant through Amazon Connect Streams. Source: [Access Connect assistant in the Connect agent workspace](https://docs.aws.amazon.com/connect/latest/adminguide/access-connect-assistant-in-workspace.html), Opening paragraphs. Checked 2026-10-01.
[^76]: AWS documentation states that Amazon Connect Customer is the current name for the product previously called Amazon Connect. Source: [What is Connect Customer?](https://docs.aws.amazon.com/connect/latest/adminguide/what-is-amazon-connect.html), Note box at top of page 'What is Connect Customer?'. Checked 2026-09-30.
[^77]: Both agent and customer call recordings are required to use conversational analytics for voice contacts. Source: [Enable conversational analytics in Connect Customer conversational analytics](https://docs.aws.amazon.com/connect/latest/adminguide/enable-analytics.html), section 'Enable call recording and speech analytics', step 2. Checked 2026-09-30.
[^78]: Analytics settings are overwritten by each subsequent Set recording and analytics behavior block in a flow; if a later block has post-call speech analytics unselected, no post-call analytics is produced for the call. Source: [Flow block in Connect Customer: Set recording and analytics behavior](https://docs.aws.amazon.com/connect/latest/adminguide/set-recording-behavior.html), section 'Configuration tips', first bullet Note and 'For calls' bullet. Checked 2026-09-30.
[^79]: In the flow designer, Save stores a draft of the flow and Publish activates it immediately, and every connector must be attached to a block before a flow can be published. Source: [Use the flow designer in Connect Customer to create flows](https://docs.aws.amazon.com/connect/latest/adminguide/create-contact-flow.html), Section Create an inbound flow, final numbered step and the following Note. Checked 2026-09-07.
[^80]: The flow designer exposes previously published versions of a flow through a Latest: Published dropdown, and a rollback is performed by opening a previous version and choosing Publish. Source: [Flow version control: Roll back a flow](https://docs.aws.amazon.com/connect/latest/adminguide/flow-version-control.html), Sections View a previous version of a flow and Roll back a flow. Checked 2026-09-07.
