To use AI agents with chat, task and email contacts, the domain's customer managed key policy must grant the connect.amazonaws.com service principal kms:Decrypt, kms:GenerateDataKey* and kms:DescribeKey.
Checked 2026-10-01
- Vendor
- Amazon Web Services
- Product
- Amazon Connect
- Subsystem
- AI agents encryption
- Deployment
- multi-tenant
- Region
- not restricted
- Release range
- current as of 2026-10-01
- Checked
- 2026-10-01
Sources
- Initial set-up for AI agents — Amazon Web Services · tier 2 current vendor documentation · Before you begin, Note; Step 2: Encrypt the domain > Use an existing key, Note
Cite this note
APA
WarmTransfer. (2026, October 1). Setting up Amazon Q in Connect for agent assist and self-service: source note amazon-connect-q-setup-kms-policy-connect-principal. WarmTransfer. https://warmtransfer.net/knowledge/claims/amazon-connect-q-setup-kms-policy-connect-principal
BibTeX
@misc{warmtransfer-claim-amazon-connect-q-setup-kms-policy-connect-principal,
title = {Setting up Amazon Q in Connect for agent assist and self-service: source note amazon-connect-q-setup-kms-policy-connect-principal},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/amazon-connect-q-setup-kms-policy-connect-principal},
note = {Source note amazon-connect-q-setup-kms-policy-connect-principal, checked 2026-10-01}
}