

Les traductions sont fournies par des outils de traduction automatique. En cas de conflit entre le contenu d'une traduction et celui de la version originale en anglais, la version anglaise prévaudra.

# Autorisations requises pour l’utilisation de politiques IAM personnalisées afin de gérer l’accès à la console Amazon Connect
<a name="security-iam-amazon-connect-permissions"></a>

Si vous utilisez des politiques [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html) personnalisées pour gérer l’accès à la console Amazon Connect, vos utilisateurs ont besoin de certaines ou de toutes les autorisations répertoriées dans cet article, en fonction des tâches qu’ils doivent effectuer. 

**Note**  
L’utilisation de `connect:*` dans une politique IAM personnalisée accorde à vos utilisateurs toutes les autorisations Amazon Connect répertoriées dans cet article.

**Note**  
Certaines pages de la console Amazon Connect, telles que [Tâches](#tasks-page) et [Profils des clients](#customer-profiles-page), nécessitent que vous ajoutiez des autorisations à vos politiques en ligne. 

**Topics**
+ [AmazonConnect\_ FullAccess politique](#amazonconnectfullaccesspolicy)
+ [AmazonConnectReadOnlyAccess politique](#amazonconnectreadonlyaccesspolicy)
+ [Page d’accueil](#console-home-page-permissions)
+ [Pages des détails](#detail-pages)
+ [Page Présentation](#overview-page)
+ [Page Téléphonie](#telephony-page)
+ [Page Stockage de données](#data-storage-page)
+ [Page Diffusion de données](#data-streaming-page)
+ [Page Flux](#contact-flows-page)
+ [Page des connecteurs Contact Lens](#contactlensconnectors-page)
+ [Page d’intégration de transferts vocaux](#voice-transfer-integrations-page)
+ [Page Intégration d’applications](#application-integration-page)
+ [Page Profils des clients](#customer-profiles-page)
+ [Page Tasks (Tâches)](#tasks-page)
+ [Page d’e-mail](#email-page)
+ [Page Cas](#cases-page)
+ [Page d’authentification du client](#customer-authentication-page)
+ [Page des campagnes sortantes](#outbound-campaigns-page)
+ [Page Connect AI pour les agents](#wisdom-page)
+ [Page Voice ID](#voiceid-page)
+ [Page Prévisions, planification et anticipation de la capacité](#forecasting-page)
+ [Fédérations](#federations)

## AWS politique gérée : AmazonConnect \_ FullAccess politique
<a name="amazonconnectfullaccesspolicy"></a>

Pour autoriser read/write un accès complet à Amazon Connect, vous devez associer deux politiques à vos utilisateurs, groupes ou rôles. Attachez la stratégie `AmazonConnect_FullAccess` et une stratégie personnalisée avec le contenu suivant :

------
#### [ JSON ]

****  

```
{ 
    "Version":"2012-10-17",		 	 	  
    "Statement": [ 
        { 
            "Sid": "AttachAnyPolicyToAmazonConnectRole", 
            "Effect": "Allow", 
            "Action": "iam:PutRolePolicy", 
            "Resource": "arn:aws:iam::*:role/aws-service-role/connect.amazonaws.com/AWSServiceRoleForAmazonConnect*" 
        } 
    ] 
}
```

------

Pour autoriser un utilisateur à créer une instance, assurez-vous qu’il dispose des autorisations accordées par la stratégie `AmazonConnect_FullAccess`.

Lorsque vous utilisez la stratégie `AmazonConnect_FullAccess`, notez les points suivants :
+ Des privilèges supplémentaires sont nécessaires pour créer un compartiment Amazon S3 portant le nom de votre choix, ou pour utiliser un compartiment existant lors de la création ou de la mise à jour d'une instance depuis le site Web Connect Customer d'administration. Si vous choisissez des emplacements de stockage par défaut pour vos enregistrements d’appels, vos transcriptions de chat, vos e-mails, vos pièces jointes, vos transcriptions d’appel et d’autres données, le système ajoute `"amazon-connect-"` au début de ces objets.
+ La clé KMS `aws/connect` peut être utilisée comme option de chiffrement par défaut. Pour utiliser une clé de chiffrement personnalisée, attribuez aux utilisateurs des privilèges KMS supplémentaires.
+ Attribuez aux utilisateurs des privilèges supplémentaires pour associer d'autres AWS ressources telles qu'Amazon Polly, Live Media Streaming, Data Streaming et Lex bots à leurs instances Amazon Connect. 

## AWS stratégie gérée : AmazonConnectReadOnlyAccess stratégie
<a name="amazonconnectreadonlyaccesspolicy"></a>

Pour autoriser l’accès en lecture seule, vous devez attacher uniquement la stratégie `AmazonConnectReadOnlyAccess`.

## Page d’accueil de la console Amazon Connect
<a name="console-home-page-permissions"></a>

L’image suivante montre un exemple de page d’accueil de la console Amazon Connect, avec une flèche pointant vers l’alias d’instance. Choisissez l’alias d’instance pour accéder aux pages détaillées de l’instance.

![Page Instances du centre de contact virtuel Amazon Connect, alias d’instance.](http://docs.aws.amazon.com/fr_fr/connect/latest/adminguide/images/instance.png)


Utilisez les autorisations répertoriées dans le tableau suivant pour gérer l’accès à cette page.


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Répertorier l’instance | `connect:ListInstances`<br />`ds:DescribeDirectories` | 
| Décrire l’instance : afficher les détails de l’instance/les paramètres actuels | `connect:DescribeInstance`<br />`connect:ListLambdaFunctions`<br />`connect:ListLexBots`<br />`connect:ListInstanceStorageConfigs`<br />`connect:ListApprovedOrigins`<br />`connect:ListSecurityKeys`<br />`connect:DescribeInstanceAttributes`<br />`connect:DescribeInstanceStorageConfig`<br />`ds:DescribeDirectories` | 
| Créer une instance | `connect:AssociateCustomerProfilesDomain`<br />`connect:CreateInstance`<br />`connect:DescribeInstance`<br />`connect:ListInstances`<br />`connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceAttribute`<br />`ds:CheckAlias`<br />`ds:CreateAlias`<br />`ds:AuthorizeApplication`<br />`ds:UnauthorizeApplication`<br />`ds:CreateIdentityPoolDirectory`<br />`ds:DescribeDirectories`<br />`iam:CreateServiceLinkedRole`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`logs:CreateLogGroup`<br />`s3:CreateBucket`<br />`s3:GetBucketLocation`<br />`s3:ListAllMyBuckets`<br />`servicequotas:GetServiceQuota`<br />`profile:CreateDomain`<br />`profile:GetDomain`<br />`profile:GetProfileObjectType`<br />`profile:ListAccountIntegrations`<br />`profile:ListDomains`<br />`profile:ListProfileObjectTypeTemplates`<br />`profile:PutIntegration` | 
| Supprimer une instance | `connect:DescribeInstance`<br />`connect:DeleteInstance`<br />`connect:ListInstances`<br />`ds:DescribeDirectories`<br />`ds:DeleteDirectory`<br />`ds:UnauthorizeApplication` | 

## Pages détaillées de l’instance
<a name="detail-pages"></a>

L’image suivante montre le menu de navigation que vous utilisez pour accéder à chacune des pages détaillées de l’instance.

![Menu de navigation sur la page des instances Amazon Connect.](http://docs.aws.amazon.com/fr_fr/connect/latest/adminguide/images/iam-custom-permissions-admin-console-telephony-page.png)


Pour accéder aux pages détaillées de l’instance, vous devez disposer d’une autorisation sur la page d’accueil de la console Amazon Connect (describe/list). Ou utilisez la stratégie `AmazonConnectReadOnlyAccess`.

Les tableaux suivants répertorient les autorisations précises pour chaque page détaillée de l’instance.

**Note**  
Pour effectuer des actions `Edit`, les utilisateurs ont également besoin des autorisations `List` et `Describe`.

## Page Présentation
<a name="overview-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Créer un rôle lié à un service | `connect:DescribeInstance`<br />`connect:ListInstances`<br />`connect:DescribeInstanceAttribute`<br />`connect:UpdateInstanceAttribute`<br />`connect:ListIntegrationAssociations`<br />`profile:ListAccountIntegrations`<br />`ds:DescribeDirectories`<br />`iam:CreateServiceLinkedRole`<br />`iam:PutRolePolicy` | 

## Page Téléphonie
<a name="telephony-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les options de téléphonie | `connect:DescribeInstance` | 
| Activer/désactiver les options de téléphonie  | `connect:UpdateInstanceAttribute` | 
| Afficher les campagnes sortantes | `connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`kms:DescribeKey` | 
| Activer/désactiver les campagnes sortantes | `connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect-campaigns:StartInstanceOnboardingJob`<br />`connect-campaigns:DeleteInstanceOnboardingJob`<br />`connect-campaigns:DeleteConnectInstanceConfig`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`connect:UpdateInstanceAttribute`<br />`iam:CreateServiceLinkedRole`<br />`iam:DeleteServiceLinkedRole`<br />`iam:AttachRolePolicy`<br />`iam:PutRolePolicy`<br />`iam:DeleteRolePolicy`<br />`events:PutRule`<br />`events:PutTargets`<br />`events:DeleteRule`<br />`events:RemoveTargets`<br />`events:DescribeRule`<br />`events:ListTargetsByRule`<br />`ds:DescribeDirectories`<br />`kms:DescribeKey`<br />`kms:ListKeys`<br />`kms:CreateGrant`<br />`kms:RetireGrant` | 

## Page Stockage de données
<a name="data-storage-page"></a>

### Section Enregistrement d’appels
<a name="call-recording-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher l’enregistrement d’appels | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| Modifier l’enregistrement d’appels | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:GetBucketAcl`<br />`s3:CreateBucket`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### Section Enregistrement d’écran
<a name="screen-recording-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher l’enregistrement d’écran | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| Modifier l’enregistrement d’écran | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:GetBucketAcl`<br />`s3:CreateBucket`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant` | 

### Section Transcriptions de chat
<a name="chat-transcripts-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les transcriptions de chat | `connect:DescribeInstance`<br />`connect:DescribeInstanceStorageConfig`<br />`connect:ListInstanceStorageConfigs` | 
| Modifier les transcriptions de chat | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:GetBucketAcl`<br />`s3:CreateBucket`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### Section Pièces jointes
<a name="attachments-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les pièces jointes | `connect:DescribeInstance`<br />`connect:DescribeInstanceStorageConfig`<br />`connect:ListInstanceStorageConfigs` | 
| Modifier les pièces jointes | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:CreateBucket`<br />`s3:GetBucketAcl`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### Section Streaming multimédia en direct
<a name="live-media-streaming-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher le streaming multimédia en direct | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| Modifier le streaming multimédia en direct | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### Section Rapports exportés
<a name="exported-reports-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les rapports exportés | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| Modifier les rapports exportés | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect: DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:CreateBucket`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`kms:CreateGrant`<br />`iam:PutRolePolicy` | 

## Page Diffusion de données
<a name="data-streaming-page"></a>

### Section Enregistrements de contact
<a name="ctr-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher le streaming de données - Enregistrements de contact | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| Modifier l’enregistrement de contact | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`firehose:ListDeliveryStreams`<br />`firehose:DescribeDeliveryStream`<br />`kinesis:ListStreams`<br />`kinesis:DescribeStream`<br />`iam:PutRolePolicy` | 

### Section Événements d’agent
<a name="agent-events-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher le streaming de données - Événements d’agent | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| Modifier les événements d’agent | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`kinesis:ListStreams`<br />`kinesis: DescribeStream`<br />`iam:PutRolePolicy` | 

## Page Flux
<a name="contact-flows-page"></a>

### Section Clés de sécurité des flux
<a name="security-keys-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les clés de sécurité de flux | `connect:DescribeInstance`<br />`connect:ListSecurityKeys` | 
| Ajouter/supprimer des clés de sécurité de flux | `connect:AssociateSecurityKey`<br />`connect:DisassociateSecurityKey` | 

### Section Robots Lex
<a name="lex-bots-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les robots Lex | `connect:ListLexBots`<br />`connect:ListBots` | 
| Ajouter/supprimer des robots Lex | `lex:GetBots`<br />`lex:GetBot`<br />`lex:CreateResourcePolicy`<br />`lex:DeleteResourcePolicy`<br />`lex:UpdateResourcePolicy`<br />`lex:DescribeBotAlias`<br />`lex:ListBotAliases`<br />`lex:ListBots`<br />`connect:AssociateBot`<br />`connect:DisassociateBot`<br />`connect:ListBots`<br />`connect:AssociateLexBot`<br />`connect:DisassociateLexBot`<br />`connect:ListLexBots`<br />`iam:PutRolePolicy` | 

### Section Fonctions Lambda
<a name="lambda-functions-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les fonctions Lambda | `connect:ListLambdaFunctions` | 
| Ajouter/supprimer des fonctions Lambda | `connect:ListLambdaFunctions`<br />`connect:AssociateLambdaFunction`<br />`connect:DisassociateLambdaFunction`<br />`iam:PutRolePolicy`<br />`lambda:ListFunctions`<br />`lambda:AddPermission`<br />`lambda:RemovePermission` | 

### Section Journaux de flux
<a name="contact-flow-logs-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher la configuration des journaux de flux | `connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute` | 
| Activer/désactiver le journal de flux | `logs:CreateLogGroup` | 

### Section Amazon Polly
<a name="amazon-polly-section"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher l’option Amazon Polly | `connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute` | 
| Mettre à jour l’option Amazon Polly | `connect:UpdateInstanceAttribute` | 

## Page des connecteurs Contact Lens
<a name="contactlensconnectors-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher des connecteurs Contact Lens | `connect:ListIntegrationAssociations`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration` | 
| Add/Update/RemoveContact Lensconnecteurs | `chime:CreateVoiceConnector`<br />`chime:DeleteVoiceConnector`<br />`chime:DeleteVoiceConnectorTermination`<br />`chime:DeleteVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:PutVoiceConnectorLoggingConfiguration`<br />`chime:PutVoiceConnectorTermination`<br />`chime:PutVoiceConnectorTerminationCredentials`<br />`chime:UpdateVoiceConnector`<br />`chime:CreateConnectAnalyticsConnector`<br />`chime:PutVoiceConnectorExternalSystemsConfiguration`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration`<br />`chime:DeleteVoiceConnectorExternalSystemsConfiguration`<br />`chime:AssociateVoiceConnectorConnect`<br />`chime:DisassociateVoiceConnectorConnect`<br />`chime:TagResources`<br />`chime:UntagResources`<br />`chime:ListTagsForResource` | 

## Page d’intégration de transferts vocaux
<a name="voice-transfer-integrations-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les connecteurs de transfert vocal externes | `connect:ListIntegrationAssociations`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration`<br />`servicequotas:GetServiceQuota` | 
| Add/Update/Removeconnecteurs de transfert vocal externes | `connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`chime:CreateConnectCallTransferConnector`<br />`chime:CreateVoiceConnector`<br />`chime:DeleteVoiceConnector`<br />`chime:DeleteVoiceConnectorTermination`<br />`chime:DeleteVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorOrigination`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:PutVoiceConnectorLoggingConfiguration`<br />`chime:PutVoiceConnectorOrigination`<br />`chime:PutVoiceConnectorTermination`<br />`chime:PutVoiceConnectorTerminationCredentials`<br />`chime:UpdateVoiceConnector`<br />`chime:CreateConnectAnalyticsConnector`<br />`chime:PutVoiceConnectorExternalSystemsConfiguration`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration`<br />`chime:DeleteVoiceConnectorExternalSystemsConfiguration`<br />`chime:AssociateVoiceConnectorConnect`<br />`chime:DisassociateVoiceConnectorConnect`<br />`chime:TagResources`<br />`chime:UntagResources`<br />`chime:ListTagsForResource`<br />`servicequotas:GetServiceQuota` | 

## Page Intégration d’applications
<a name="application-integration-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les origines approuvées | `connect:DescribeInstance`<br />`connect:ListApprovedOrigins` | 
| Modifier les origines approuvées | `connect: AssociateApprovedOrigin`<br />`connect:ListApprovedOrigins`<br />`connect:DisassociateApprovedOrigin` | 

## Page Profils des clients
<a name="customer-profiles-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les profils des clients | `app-integrations:ListEventIntegrations`<br />`appflow:DescribeConnectorEntity`<br />`appflow:DescribeConnectorProfiles`<br />`appflow:DescribeFlow`<br />`appflow:ListFlows`<br />`appflow:ListConnectorEntities`<br />`appflow:ListConnectorProfiles`<br />`cloudwatch:GetMetricData`<br />`connect:DescribeInstance`<br />`connect:ListInstances`<br />`ds:DescribeDirectories`<br />`iam:ListRoles`<br />`kinesis:DescribeStreamSummary`<br />`kms:Decrypt`<br />`kms:DescribeKey`<br />`kms:GenerateDataKey`<br />`kms:ListKeys`<br />`profile:GetCalculatedAttributeDefinition`<br />`profile:GetDomain`<br />`profile:GetEventStream`<br />`profile:GetIdentityResolutionJob`<br />`profile:GetIntegration`<br />`profile:GetProfileObjectType`<br />`profile:GetProfileObjectTypeTemplate`<br />`profile:GetWorkflow`<br />`profile:ListAccountIntegrations`<br />`profile:ListCalculatedAttributeDefinitions`<br />`profile:ListDomains`<br />`profile:ListDomainLayouts`<br />`profile:ListEventStreams`<br />`profile:ListIdentityResolutionJobs`<br />`profile:ListIntegrations`<br />`profile:ListProfileObjectTypes`<br />`profile:ListProfileObjectTypeTemplates`<br />`profile:ListRecommenders`<br />`profile:ListSegmentDefinitions`<br />`sqs:ListQueues` | 
| Modifier les profils des clients | `app-integrations:CreateEventIntegration`<br />`app-integrations:ListEventIntegrations`<br />`appflow:CreateFlow`<br />`appflow:CreateConnectorProfile`<br />`appflow:DescribeFlow`<br />`appflow:DeleteFlow`<br />`appflow:DescribeConnectorEntity`<br />`appflow:DescribeConnectorProfiles`<br />`appflow:ListFlows`<br />`appflow:ListConnectorEntities`<br />`appflow:ListConnectorProfiles`<br />`appflow:StartFlow`<br />`cloudwatch:GetMetricData`<br />`connect:DescribeInstance`<br />`connect:ListInstances`<br />`ds:DescribeDirectories`<br />`events:CreateEventBus`<br />`events:DescribeEventBus`<br />`events:DescribeEventSource`<br />`events:ListEventSources`<br />`iam:CreateRole`<br />`iam:CreatePolicy`<br />`iam:AttachRolePolicy`<br />`iam:ListRoles`<br />`iam:PutRolePolicy`<br />`kinesis:DescribeStreamSummary`<br />`kinesis:ListStreams`<br />`kms:CreateGrant`<br />`kms:Decrypt`<br />`kms:DescribeKey`<br />`kms:GenerateDataKey`<br />`kms:ListAliases`<br />`kms:ListKeys`<br />`kms:ListGrants`<br />`profile:CreateCalculatedAttributeDefinition`<br />`profile:CreateDomain`<br />`profile:CreateDomainLayout`<br />`profile:CreateEventStream`<br />`profile:CreateIntegrationWorkflow`<br />`profile:CreateSegmentDefinition`<br />`profile:DeleteEventStream`<br />`profile:DeleteIntegration`<br />`profile:DeleteDomain`<br />`profile:DeleteProfileObjectType`<br />`profile:DetectProfileObjectType`<br />`profile:GetCalculatedAttributeDefinition`<br />`profile:GetDomain`<br />`profile:GetEventStream`<br />`profile:GetIdentityResolutionJob`<br />`profile:GetIntegration`<br />`profile:GetProfileObjectType`<br />`profile:GetProfileObjectTypeTemplate`<br />`profile:GetWorkflow`<br />`profile:ListAccountIntegrations`<br />`profile:ListCalculatedAttributeDefinitions`<br />`profile:ListDomains`<br />`profile:ListDomainLayouts`<br />`profile:ListEventStreams`<br />`profile:ListIdentityResolutionJobs`<br />`profile:ListIntegrations`<br />`profile:ListProfileObjectTypes`<br />`profile:ListProfileObjectTypeTemplates`<br />`profile:ListSegmentDefinitions`<br />`profile:PutIntegration`<br />`profile:PutProfileObjectType`<br />`profile:TagResource`<br />`profile:UntagResource`<br />`profile:UpdateDomain`<br />`s3:GetBucketLocation`<br />`s3:GetBucketPolicy`<br />`s3:GetObject`<br />`s3:HeadBucket`<br />`s3:ListAllMyBuckets`<br />`s3:ListBucket`<br />`s3:ListObjectsV2`<br />`s3:PutBucketPolicy`<br />`s3:SelectObjectContent`<br />`sqs:ListQueues` | 

## Page Tasks (Tâches)
<a name="tasks-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les intégrations de tâches | `app-integrations:GetEventIntegration`<br />`connect:ListIntegrationAssociations` | 
| Modifier les intégrations de tâches | `app-integrations:CreateEventIntegration`<br />`app-integrations:GetEventIntegration`<br />`app-integrations:ListEventIntegrations`<br />`app-integrations:DeleteEventIntegrationAssociation`<br />`app-integrations:CreateEventIntegrationAssociation`<br />`appflow:CreateFlow`<br />`appflow:CreateConnectorProfile`<br />`appflow:DescribeFlow`<br />`appflow:DeleteFlow`<br />`appflow:DeleteConnectorProfile`<br />`appflow:DescribeConnectorEntity`<br />`appflow:ListFlows`<br />`appflow:ListConnectorEntities`<br />`appflow:StartFlow`<br />`connect:ListIntegrationAssociations`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListUseCases`<br />`connect:DeleteUseCase`<br />`events:ActivateEventSource`<br />`events:CreateEventBus`<br />`events:DescribeEventBus`<br />`events:DescribeEventSource`<br />`events:ListEventSources`<br />`events:ListTargetsByRule`<br />`events:PutRule`<br />`events:PutTargets`<br />`events:DeleteRule`<br />`events:RemoveTargets`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:ListKeys`<br />`kms:ListGrants` | 

## Page d’e-mail
<a name="email-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les domaines et adresses e-mail | `ses:GetIdentityVerificationAttributes`<br />`ses:DescribeReceiptRule`<br />`ses:DescribeActiveReceiptRuleSet`<br />`ses:GetEmailIdentity`<br />`ses:DescribeReceiptRuleSet`<br />`ses:GetConfigurationSetEventDestinations`<br />`ses:GetConfigurationSet` | 
| Modifier les domaines et adresses e-mail | `ses:CreateReceiptRule`<br />`ses:UpdateReceiptRule`<br />`ses:SetActiveReceiptRuleSet`<br />`ses:CreateReceiptRuleSet`<br />`ses:CreateEmailIdentity`<br />`ses:TagResource`<br />`ses:UntagResource`<br />`ses:DeleteReceiptRule`<br />`ses:DeleteReceiptRuleSet`<br />`ses:CloneReceiptRuleSet`<br />`ses:CreateConfigurationSet`<br />`ses:CreateConfigurationSetEventDestination`<br />`ses:PutEmailIdentityConfigurationSetAttributes`<br />`ses:CreateEmailIdentityPolicy`<br />`ses:UpdateEmailIdentityPolicy`<br />`ses:DeleteEmailIdentityPolicy`<br />`iam:CreateServiceLinkedRole`<br />`iam:PassRole`<br />`iam:CreateRole`<br />`iam:CreatePolicy` | 

## Page Cas
<a name="cases-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Affichage des détails du domaine Cas | `connect:ListInstances`<br />`ds:DescribeDirectories`<br />`connect:ListIntegrationAssociations`<br />`cases:GetDomain` | 
| Intégration à la fonctionnalité Cas | `connect:ListInstances`<br />`connect:ListIntegrationAssociations`<br />`cases:GetDomain`<br />`cases:CreateDomain`<br />`connect:CreateIntegrationAssociation`<br />`connect:DescribeInstance`<br />`iam:PutRolePolicy` | 

## Page d’authentification du client
<a name="customer-authentication-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher l’authentification du client | `connect:ListIntegrationAssociations`<br />`cognito-idp:ListUserPools`<br />`cognito-idp:DescribeUserPool` | 
| Intégrer à l’authentification du client | `connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`cognito-idp:ListUserPools`<br />`cognito-idp:DescribeUserPool`<br />`cognito-idp:ListUserPoolClients`<br />`cognito-idp:TagResource`<br />`cognito-idp:CreateUserPool` | 

## Page des campagnes sortantes
<a name="outbound-campaigns-page"></a>


|  Action/Cas d’utilisation  |  Autorisations nécessaires  | 
| --- | --- | 
|  Afficher les campagnes sortantes  | `connect:ListIntegrationAssociations`<br />`connect:ListPhoneNumbersV2`<br />`connect:SearchEmailAddresses`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`kms:DescribeKey`<br />`kms:ListKeys`<br />`profile:ListAccountIntegrations`<br />`profile:ListIntegrations`<br />`profile:ListDomains`<br />`profile:GetDomain`<br />`wisdom:ListKnowledgeBases`<br />`wisdom:GetKnowledgeBase`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:ListConnectInstanceIntegrations` | 
|  Créer des campagnes sortantes  | `connect-campaigns:StartInstanceOnboardingJob`<br />`connect-campaigns:DeleteInstanceOnboardingJob`<br />`connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect-campaigns:DeleteConnectInstanceConfig`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`connect:UpdateInstanceAttribute`<br />`iam:CreateServiceLinkedRole`<br />`iam:DeleteServiceLinkedRole`<br />`iam:AttachRolePolicy`<br />`iam:PutRolePolicy`<br />`iam:DeleteRolePolicy`<br />`events:PutRule`<br />`events:PutTargets`<br />`events:DeleteRule`<br />`events:RemoveTargets`<br />`events:DescribeRule`<br />`events:ListTargetsByRule`<br />`ds:DescribeDirectories`<br />`kms:DescribeKey`<br />`kms:ListKeys`<br />`kms:CreateGrant`<br />`kms:RetireGrant`<br />`profile:CreateDomain`<br />`profile:ListAccountIntegrations`<br />`profile:ListIntegrations`<br />`profile:PutIntegration`<br />`profile:PutProfileObjectType`<br />`connect:CreateIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`connect:UpdateInstanceAttribute`<br />`connect:AssociateCustomerProfilesDomain`<br />`connect-campaigns:ListConnectInstanceIntegrations`<br />`connect-campaigns:PutConnectInstanceIntegration`<br />`wisdom:CreateKnowledgeBase`<br />`wisdom:ListKnowledgeBases` | 

## Page Connect AI pour les agents
<a name="wisdom-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Afficher les domaines et les intégrations | `wisdom:ListAssistantAssociations`<br />`appflow:DescribeConnectorProfiles`<br />`app-integrations:GetDataIntegration`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`connect:ListIntegrationAssociations`<br />`kms:DescribeKey`<br />`kms:ListGrants`<br />`wisdom:GetAssistant`<br />`wisdom:GetKnowledgeBase`<br />`wisdom:ListAssistantAssociations` | 
| Ajouter ou supprimer des domaines | `connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`iam:DeleteRolePolicy`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`wisdom:CreateAssistant`<br />`wisdom:DeleteAssistant`<br />`wisdom:GetAssistant`<br />`wisdom:ListAssistantAssociations`<br />`wisdom:ListAssistants`<br />`wisdom:TagResource` | 
| Ajouter ou supprimer des intégrations | `wisdom:ListAssistantAssociations`<br />`app-integrations:CreateDataIntegration`<br />`app-integrations:CreateDataIntegrationAssociation`<br />`app-integrations:DeleteDataIntegrationAssociation`<br />`app-integrations:GetDataIntegration`<br />`app-integrations:ListDataIntegrations`<br />`appflow:CreateConnectorProfile`<br />`appflow:CreateFlow`<br />`appflow:DeleteFlow`<br />`appflow:DescribeConnector`<br />`appflow:DescribeConnectorEntity`<br />`appflow:DescribeConnectorProfiles`<br />`appflow:DescribeConnectors`<br />`appflow:DescribeFlow`<br />`appflow:ListConnectorEntities`<br />`appflow:StartFlow`<br />`appflow:StopFlow`<br />`appflow:TagResource`<br />`appflow:UseConnectorProfile`<br />`connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`iam:DeleteRolePolicy`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:Decrypt`<br />`kms:DescribeKey`<br />`kms:GenerateDataKey`<br />`kms:ListAliases`<br />`kms:ListGrants`<br />`secretsmanager:CreateSecret`<br />`secretsmanager:PutResourcePolicy`<br />`wisdom:CreateAssistantAssociation`<br />`wisdom:CreateKnowledgeBase`<br />`wisdom:DeleteAssistantAssociation`<br />`wisdom:DeleteKnowledgeBase`<br />`wisdom:GetAssistant`<br />`wisdom:GetKnowledgeBase`<br />`wisdom:ListAssistantAssociations`<br />`wisdom:ListKnowledgeBases`<br />`wisdom:TagResource` | 

## Page Voice ID
<a name="voiceid-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Affichage des intégrations Voice ID | `voiceid:DescribeDomain`<br />`voiceid:ListDomains`<br />`voiceid:RegisterComplianceConsent`<br />`voiceid:DescribeComplianceConsent`<br />`connect:ListIntegrationAssociations` | 
| Modification des intégrations Voice ID | `voiceid:DescribeDomain`<br />`voiceid:ListDomains`<br />`voiceid:RegisterComplianceConsent`<br />`voiceid:DescribeComplianceConsent`<br />`voiceid:UpdateDomain`<br />`voiceid:CreateDomain`<br />`connect:ListIntegrationAssociations`<br />`connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`events:PutRule`<br />`events:DeleteRule`<br />`events:PutTargets`<br />`events:RemoveTargets`<br />`iam:PutRolePolicy` | 

## Page Prévisions, planification et anticipation de la capacité
<a name="forecasting-page"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Affichage de la fonctionnalité Prévisions, planification et anticipation de la capacité | `connect:DescribeForecastingPlanningSchedulingIntegration` | 
| Activation de Prévisions, planification et anticipation de la capacité | `connect:UpdateInstanceAttribute`<br />`connect:StartForecastingPlanningSchedulingIntegration` | 
| Désactivation de la fonctionnalité Prévisions, planification et anticipation de la capacité | `connect:UpdateInstanceAttribute`<br />`connect:StopForecastingPlanningSchedulingIntegration` | 

## Fédérations
<a name="federations"></a>

### Fédération SAML
<a name="saml-federation"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Fédération SAML | `connect:GetFederationToken` | 

### Fédération administrative/d’urgence
<a name="admin-emergency-federation"></a>


| Action/Cas d’utilisation | Autorisations nécessaires | 
| --- | --- | 
| Fédération administrative/d'urgence | `connect:AdminGetEmergencyAccessToken` | 