

本文属于机器翻译版本。若本译文内容与英语原文存在差异，则一律以英文原文为准。

# 使用自定义 IAM 策略管理对 Amazon Connect 控制台的访问权限所需的权限
<a name="security-iam-amazon-connect-permissions"></a>

如果您使用自定义 [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html) 策略来管理对 Amazon Connect 控制台的访问权限，则您的用户需要本文中列出的部分或全部权限，具体取决于他们需要执行的任务。

**注意**  
在自定义 IAM 策略中使用 `connect:*` 可以向您的用户授予本文中列出的所有 Amazon Connect 权限。

**注意**  
Amazon Connect 控制台上的某些页面（例如[任务](#tasks-page)和[客户资料](#customer-profiles-page)）要求您为内联策略添加权限。

**Topics**
+ [AmazonConnect\_ FullAccess 政策](#amazonconnectfullaccesspolicy)
+ [AmazonConnectReadOnlyAccess 政策](#amazonconnectreadonlyaccesspolicy)
+ [主页](#console-home-page-permissions)
+ [详细信息页面](#detail-pages)
+ [“概述”页面](#overview-page)
+ [“电话”页面](#telephony-page)
+ [“数据存储”页面](#data-storage-page)
+ [“数据流式处理”页面](#data-streaming-page)
+ [“流”页面](#contact-flows-page)
+ [Contact Lens 连接器页面](#contactlensconnectors-page)
+ [语音转接集成页面](#voice-transfer-integrations-page)
+ [“应用程序集成”页面](#application-integration-page)
+ [“客户资料”页面](#customer-profiles-page)
+ [“任务”页面](#tasks-page)
+ [电子邮件页面](#email-page)
+ [“案例”页面](#cases-page)
+ [客户身份验证页面](#customer-authentication-page)
+ [出站活动页面](#outbound-campaigns-page)
+ [Connect 人工智能代理页面](#wisdom-page)
+ [“Voice ID”页面](#voiceid-page)
+ [“预测、容量规划和调度”页面](#forecasting-page)
+ [联合身份验证](#federations)

## AWS 托管策略: AmazonConnect\_ FullAccess 策略
<a name="amazonconnectfullaccesspolicy"></a>

要允许完全 read/write 访问 Amazon Connect，您必须为用户、群组或角色附加两项策略。附加 `AmazonConnect_FullAccess` 策略和包含以下内容的自定义策略：

------
#### [ JSON ]

****  

```
{ 
    "Version":"2012-10-17",		 	 	  
    "Statement": [ 
        { 
            "Sid": "AttachAnyPolicyToAmazonConnectRole", 
            "Effect": "Allow", 
            "Action": "iam:PutRolePolicy", 
            "Resource": "arn:aws:iam::*:role/aws-service-role/connect.amazonaws.com/AWSServiceRoleForAmazonConnect*" 
        } 
    ] 
}
```

------

要允许用户创建实例，请确保他们具有 `AmazonConnect_FullAccess` 策略授予的权限。

当您使用 `AmazonConnect_FullAccess` 策略时，请注意以下几点：
+ 要使用您选择的名称创建 Amazon S3 存储桶，或者在 Connect Customer 管理网站上创建或更新实例时使用现有存储桶，则需要额外的权限。如果您为通话录音、聊天转录、电子邮件内容、附件、通话转录和其它数据选择默认存储位置，则系统会在这些对象前加上 `"amazon-connect-"`。
+ `aws/connect` KMS 密钥可用作默认加密选项。要使用自定义加密密钥，请为用户分配其他 KMS 权限。
+ 为用户分配额外权限，以便将 Amazon Polly、直播媒体流、数据流和 Lex 机器人等其他 AWS 资源附加到他们的 Amazon Connect 实例。

## AWS 托管策略: AmazonConnectReadOnlyAccess 策略
<a name="amazonconnectreadonlyaccesspolicy"></a>

要允许只读访问，您只需附加 `AmazonConnectReadOnlyAccess` 策略。

## Amazon Connect 控制台主页
<a name="console-home-page-permissions"></a>

下图显示了一个 Amazon Connect 控制台主页示例，其中一个箭头指向实例别名。选择实例别名可导航到详细的实例页面。

![Amazon Connect 虚拟联系中心实例页面，实例别名。](http://docs.aws.amazon.com/zh_cn/connect/latest/adminguide/images/instance.png)


使用下表中列出的权限来管理对此页面的访问。


| 操作/使用案例 | 所需权限 | 
| --- | --- | 
| 列出实例 | `connect:ListInstances`<br />`ds:DescribeDirectories` | 
| 描述实例：查看实例/当前设置的详细信息 | `connect:DescribeInstance`<br />`connect:ListLambdaFunctions`<br />`connect:ListLexBots`<br />`connect:ListInstanceStorageConfigs`<br />`connect:ListApprovedOrigins`<br />`connect:ListSecurityKeys`<br />`connect:DescribeInstanceAttributes`<br />`connect:DescribeInstanceStorageConfig`<br />`ds:DescribeDirectories` | 
| 创建实例 | `connect:AssociateCustomerProfilesDomain`<br />`connect:CreateInstance`<br />`connect:DescribeInstance`<br />`connect:ListInstances`<br />`connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceAttribute`<br />`ds:CheckAlias`<br />`ds:CreateAlias`<br />`ds:AuthorizeApplication`<br />`ds:UnauthorizeApplication`<br />`ds:CreateIdentityPoolDirectory`<br />`ds:DescribeDirectories`<br />`iam:CreateServiceLinkedRole`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`logs:CreateLogGroup`<br />`s3:CreateBucket`<br />`s3:GetBucketLocation`<br />`s3:ListAllMyBuckets`<br />`servicequotas:GetServiceQuota`<br />`profile:CreateDomain`<br />`profile:GetDomain`<br />`profile:GetProfileObjectType`<br />`profile:ListAccountIntegrations`<br />`profile:ListDomains`<br />`profile:ListProfileObjectTypeTemplates`<br />`profile:PutIntegration` | 
| 删除实例 | `connect:DescribeInstance`<br />`connect:DeleteInstance`<br />`connect:ListInstances`<br />`ds:DescribeDirectories`<br />`ds:DeleteDirectory`<br />`ds:UnauthorizeApplication` | 

## 详细的实例页面
<a name="detail-pages"></a>

下图显示了您用于访问每个详细实例页面的导航菜单。

![Amazon Connect 实例页面上的导航菜单。](http://docs.aws.amazon.com/zh_cn/connect/latest/adminguide/images/iam-custom-permissions-admin-console-telephony-page.png)


要访问详细的实例页面，您需要访问 Amazon Connect 控制台主页的权限（描述/列出）。或者，使用 `AmazonConnectReadOnlyAccess` 策略。

下表列出了每个详细实例页面的精细权限。

**注意**  
要执行 `Edit` 操作，用户还需要 `List` 和 `Describe` 权限。

## “概述”页面
<a name="overview-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 创建服务相关角色 | `connect:DescribeInstance`<br />`connect:ListInstances`<br />`connect:DescribeInstanceAttribute`<br />`connect:UpdateInstanceAttribute`<br />`connect:ListIntegrationAssociations`<br />`profile:ListAccountIntegrations`<br />`ds:DescribeDirectories`<br />`iam:CreateServiceLinkedRole`<br />`iam:PutRolePolicy` | 

## “电话”页面
<a name="telephony-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看电话选项 | `connect:DescribeInstance` | 
| 启用/禁用电话选项  | `connect:UpdateInstanceAttribute` | 
| 查看出站活动 | `connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`kms:DescribeKey` | 
| 启用/禁用出站活动 | `connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect-campaigns:StartInstanceOnboardingJob`<br />`connect-campaigns:DeleteInstanceOnboardingJob`<br />`connect-campaigns:DeleteConnectInstanceConfig`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`connect:UpdateInstanceAttribute`<br />`iam:CreateServiceLinkedRole`<br />`iam:DeleteServiceLinkedRole`<br />`iam:AttachRolePolicy`<br />`iam:PutRolePolicy`<br />`iam:DeleteRolePolicy`<br />`events:PutRule`<br />`events:PutTargets`<br />`events:DeleteRule`<br />`events:RemoveTargets`<br />`events:DescribeRule`<br />`events:ListTargetsByRule`<br />`ds:DescribeDirectories`<br />`kms:DescribeKey`<br />`kms:ListKeys`<br />`kms:CreateGrant`<br />`kms:RetireGrant` | 

## “数据存储”页面
<a name="data-storage-page"></a>

### “通话录音”部分
<a name="call-recording-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看通话录音 | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| 编辑通话录音 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:GetBucketAcl`<br />`s3:CreateBucket`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### “屏幕录制”部分
<a name="screen-recording-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看屏幕录制 | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| 编辑屏幕录制 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:GetBucketAcl`<br />`s3:CreateBucket`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant` | 

### “聊天转录”部分
<a name="chat-transcripts-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看聊天转录 | `connect:DescribeInstance`<br />`connect:DescribeInstanceStorageConfig`<br />`connect:ListInstanceStorageConfigs` | 
| 编辑聊天转录 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:GetBucketAcl`<br />`s3:CreateBucket`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### “附件”部分
<a name="attachments-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看附件 | `connect:DescribeInstance`<br />`connect:DescribeInstanceStorageConfig`<br />`connect:ListInstanceStorageConfigs` | 
| 编辑附件 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:CreateBucket`<br />`s3:GetBucketAcl`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### “实时媒体流式传输”部分
<a name="live-media-streaming-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看实时媒体流式传输 | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| 编辑实时媒体流式传输 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:RetireGrant`<br />`iam:PutRolePolicy` | 

### “导出的报告”部分
<a name="exported-reports-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看导出的报告 | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| 编辑导出的报告 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect: DisassociateInstanceStorageConfig`<br />`s3:ListAllMyBuckets`<br />`s3:GetBucketLocation`<br />`s3:CreateBucket`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:RetireGrant`<br />`kms:CreateGrant`<br />`iam:PutRolePolicy` | 

## “数据流式处理”页面
<a name="data-streaming-page"></a>

### “联系记录”部分
<a name="ctr-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看数据流式处理 – 联系记录 | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| 编辑联系记录 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`firehose:ListDeliveryStreams`<br />`firehose:DescribeDeliveryStream`<br />`kinesis:ListStreams`<br />`kinesis:DescribeStream`<br />`iam:PutRolePolicy` | 

### “座席事件”部分
<a name="agent-events-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看数据流式处理 – 座席事件 | `connect:DescribeInstance`<br />`connect:ListInstanceStorageConfigs`<br />`connect:DescribeInstanceStorageConfig` | 
| 编辑座席事件 | `connect:AssociateInstanceStorageConfig`<br />`connect:UpdateInstanceStorageConfig`<br />`connect:DisassociateInstanceStorageConfig`<br />`kinesis:ListStreams`<br />`kinesis: DescribeStream`<br />`iam:PutRolePolicy` | 

## “流”页面
<a name="contact-flows-page"></a>

### “流安全密钥”部分
<a name="security-keys-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看流安全密钥 | `connect:DescribeInstance`<br />`connect:ListSecurityKeys` | 
| 添加/删除流安全密钥 | `connect:AssociateSecurityKey`<br />`connect:DisassociateSecurityKey` | 

### “Lex 自动程序”部分
<a name="lex-bots-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看 Lex 自动程序 | `connect:ListLexBots`<br />`connect:ListBots` | 
| 添加/删除 Lex 自动程序 | `lex:GetBots`<br />`lex:GetBot`<br />`lex:CreateResourcePolicy`<br />`lex:DeleteResourcePolicy`<br />`lex:UpdateResourcePolicy`<br />`lex:DescribeBotAlias`<br />`lex:ListBotAliases`<br />`lex:ListBots`<br />`connect:AssociateBot`<br />`connect:DisassociateBot`<br />`connect:ListBots`<br />`connect:AssociateLexBot`<br />`connect:DisassociateLexBot`<br />`connect:ListLexBots`<br />`iam:PutRolePolicy` | 

### “Lambda 函数”部分
<a name="lambda-functions-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看 Lambda 函数 | `connect:ListLambdaFunctions` | 
| 添加/删除 Lambda 函数 | `connect:ListLambdaFunctions`<br />`connect:AssociateLambdaFunction`<br />`connect:DisassociateLambdaFunction`<br />`iam:PutRolePolicy`<br />`lambda:ListFunctions`<br />`lambda:AddPermission`<br />`lambda:RemovePermission` | 

### “流日志”部分
<a name="contact-flow-logs-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看流日志配置 | `connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute` | 
| 启用/禁用流日志 | `logs:CreateLogGroup` | 

### “Amazon Polly”部分
<a name="amazon-polly-section"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看 Amazon Polly 选项 | `connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute` | 
| 更新 Amazon Polly 选项 | `connect:UpdateInstanceAttribute` | 

## Contact Lens 连接器页面
<a name="contactlensconnectors-page"></a>


| 操作/使用案例 | 所需权限 | 
| --- | --- | 
| 查看 Contact Lens 连接器 | `connect:ListIntegrationAssociations`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration` | 
| Add/Update/RemoveContact Lens连接器 | `chime:CreateVoiceConnector`<br />`chime:DeleteVoiceConnector`<br />`chime:DeleteVoiceConnectorTermination`<br />`chime:DeleteVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:PutVoiceConnectorLoggingConfiguration`<br />`chime:PutVoiceConnectorTermination`<br />`chime:PutVoiceConnectorTerminationCredentials`<br />`chime:UpdateVoiceConnector`<br />`chime:CreateConnectAnalyticsConnector`<br />`chime:PutVoiceConnectorExternalSystemsConfiguration`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration`<br />`chime:DeleteVoiceConnectorExternalSystemsConfiguration`<br />`chime:AssociateVoiceConnectorConnect`<br />`chime:DisassociateVoiceConnectorConnect`<br />`chime:TagResources`<br />`chime:UntagResources`<br />`chime:ListTagsForResource` | 

## 语音转接集成页面
<a name="voice-transfer-integrations-page"></a>


| 操作/使用案例 | 所需权限 | 
| --- | --- | 
| 查看外部语音转接连接器 | `connect:ListIntegrationAssociations`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration`<br />`servicequotas:GetServiceQuota` | 
| Add/Update/Remove外部语音传输连接器 | `connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`chime:CreateConnectCallTransferConnector`<br />`chime:CreateVoiceConnector`<br />`chime:DeleteVoiceConnector`<br />`chime:DeleteVoiceConnectorTermination`<br />`chime:DeleteVoiceConnectorTerminationCredentials`<br />`chime:GetVoiceConnector`<br />`chime:GetVoiceConnectorLoggingConfiguration`<br />`chime:GetVoiceConnectorOrigination`<br />`chime:GetVoiceConnectorTermination`<br />`chime:GetVoiceConnectorTerminationHealth`<br />`chime:ListVoiceConnectors`<br />`chime:ListVoiceConnectorTerminationCredentials`<br />`chime:PutVoiceConnectorLoggingConfiguration`<br />`chime:PutVoiceConnectorOrigination`<br />`chime:PutVoiceConnectorTermination`<br />`chime:PutVoiceConnectorTerminationCredentials`<br />`chime:UpdateVoiceConnector`<br />`chime:CreateConnectAnalyticsConnector`<br />`chime:PutVoiceConnectorExternalSystemsConfiguration`<br />`chime:GetVoiceConnectorExternalSystemsConfiguration`<br />`chime:DeleteVoiceConnectorExternalSystemsConfiguration`<br />`chime:AssociateVoiceConnectorConnect`<br />`chime:DisassociateVoiceConnectorConnect`<br />`chime:TagResources`<br />`chime:UntagResources`<br />`chime:ListTagsForResource`<br />`servicequotas:GetServiceQuota` | 

## “应用程序集成”页面
<a name="application-integration-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看批准的源 | `connect:DescribeInstance`<br />`connect:ListApprovedOrigins` | 
| 编辑批准的源 | `connect: AssociateApprovedOrigin`<br />`connect:ListApprovedOrigins`<br />`connect:DisassociateApprovedOrigin` | 

## “客户资料”页面
<a name="customer-profiles-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看客户资料 | `app-integrations:ListEventIntegrations`<br />`appflow:DescribeConnectorEntity`<br />`appflow:DescribeConnectorProfiles`<br />`appflow:DescribeFlow`<br />`appflow:ListFlows`<br />`appflow:ListConnectorEntities`<br />`appflow:ListConnectorProfiles`<br />`cloudwatch:GetMetricData`<br />`connect:DescribeInstance`<br />`connect:ListInstances`<br />`ds:DescribeDirectories`<br />`iam:ListRoles`<br />`kinesis:DescribeStreamSummary`<br />`kms:Decrypt`<br />`kms:DescribeKey`<br />`kms:GenerateDataKey`<br />`kms:ListKeys`<br />`profile:GetCalculatedAttributeDefinition`<br />`profile:GetDomain`<br />`profile:GetEventStream`<br />`profile:GetIdentityResolutionJob`<br />`profile:GetIntegration`<br />`profile:GetProfileObjectType`<br />`profile:GetProfileObjectTypeTemplate`<br />`profile:GetWorkflow`<br />`profile:ListAccountIntegrations`<br />`profile:ListCalculatedAttributeDefinitions`<br />`profile:ListDomains`<br />`profile:ListDomainLayouts`<br />`profile:ListEventStreams`<br />`profile:ListIdentityResolutionJobs`<br />`profile:ListIntegrations`<br />`profile:ListProfileObjectTypes`<br />`profile:ListProfileObjectTypeTemplates`<br />`profile:ListRecommenders`<br />`profile:ListSegmentDefinitions`<br />`sqs:ListQueues` | 
| 编辑客户资料 | `app-integrations:CreateEventIntegration`<br />`app-integrations:ListEventIntegrations`<br />`appflow:CreateFlow`<br />`appflow:CreateConnectorProfile`<br />`appflow:DescribeFlow`<br />`appflow:DeleteFlow`<br />`appflow:DescribeConnectorEntity`<br />`appflow:DescribeConnectorProfiles`<br />`appflow:ListFlows`<br />`appflow:ListConnectorEntities`<br />`appflow:ListConnectorProfiles`<br />`appflow:StartFlow`<br />`cloudwatch:GetMetricData`<br />`connect:DescribeInstance`<br />`connect:ListInstances`<br />`ds:DescribeDirectories`<br />`events:CreateEventBus`<br />`events:DescribeEventBus`<br />`events:DescribeEventSource`<br />`events:ListEventSources`<br />`iam:CreateRole`<br />`iam:CreatePolicy`<br />`iam:AttachRolePolicy`<br />`iam:ListRoles`<br />`iam:PutRolePolicy`<br />`kinesis:DescribeStreamSummary`<br />`kinesis:ListStreams`<br />`kms:CreateGrant`<br />`kms:Decrypt`<br />`kms:DescribeKey`<br />`kms:GenerateDataKey`<br />`kms:ListAliases`<br />`kms:ListKeys`<br />`kms:ListGrants`<br />`profile:CreateCalculatedAttributeDefinition`<br />`profile:CreateDomain`<br />`profile:CreateDomainLayout`<br />`profile:CreateEventStream`<br />`profile:CreateIntegrationWorkflow`<br />`profile:CreateSegmentDefinition`<br />`profile:DeleteEventStream`<br />`profile:DeleteIntegration`<br />`profile:DeleteDomain`<br />`profile:DeleteProfileObjectType`<br />`profile:DetectProfileObjectType`<br />`profile:GetCalculatedAttributeDefinition`<br />`profile:GetDomain`<br />`profile:GetEventStream`<br />`profile:GetIdentityResolutionJob`<br />`profile:GetIntegration`<br />`profile:GetProfileObjectType`<br />`profile:GetProfileObjectTypeTemplate`<br />`profile:GetWorkflow`<br />`profile:ListAccountIntegrations`<br />`profile:ListCalculatedAttributeDefinitions`<br />`profile:ListDomains`<br />`profile:ListDomainLayouts`<br />`profile:ListEventStreams`<br />`profile:ListIdentityResolutionJobs`<br />`profile:ListIntegrations`<br />`profile:ListProfileObjectTypes`<br />`profile:ListProfileObjectTypeTemplates`<br />`profile:ListSegmentDefinitions`<br />`profile:PutIntegration`<br />`profile:PutProfileObjectType`<br />`profile:TagResource`<br />`profile:UntagResource`<br />`profile:UpdateDomain`<br />`s3:GetBucketLocation`<br />`s3:GetBucketPolicy`<br />`s3:GetObject`<br />`s3:HeadBucket`<br />`s3:ListAllMyBuckets`<br />`s3:ListBucket`<br />`s3:ListObjectsV2`<br />`s3:PutBucketPolicy`<br />`s3:SelectObjectContent`<br />`sqs:ListQueues` | 

## “任务”页面
<a name="tasks-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看任务集成 | `app-integrations:GetEventIntegration`<br />`connect:ListIntegrationAssociations` | 
| 编辑任务集成 | `app-integrations:CreateEventIntegration`<br />`app-integrations:GetEventIntegration`<br />`app-integrations:ListEventIntegrations`<br />`app-integrations:DeleteEventIntegrationAssociation`<br />`app-integrations:CreateEventIntegrationAssociation`<br />`appflow:CreateFlow`<br />`appflow:CreateConnectorProfile`<br />`appflow:DescribeFlow`<br />`appflow:DeleteFlow`<br />`appflow:DeleteConnectorProfile`<br />`appflow:DescribeConnectorEntity`<br />`appflow:ListFlows`<br />`appflow:ListConnectorEntities`<br />`appflow:StartFlow`<br />`connect:ListIntegrationAssociations`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListUseCases`<br />`connect:DeleteUseCase`<br />`events:ActivateEventSource`<br />`events:CreateEventBus`<br />`events:DescribeEventBus`<br />`events:DescribeEventSource`<br />`events:ListEventSources`<br />`events:ListTargetsByRule`<br />`events:PutRule`<br />`events:PutTargets`<br />`events:DeleteRule`<br />`events:RemoveTargets`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`kms:ListKeys`<br />`kms:ListGrants` | 

## 电子邮件页面
<a name="email-page"></a>


| 操作/使用案例 | 所需权限 | 
| --- | --- | 
| 查看电子邮件域和地址 | `ses:GetIdentityVerificationAttributes`<br />`ses:DescribeReceiptRule`<br />`ses:DescribeActiveReceiptRuleSet`<br />`ses:GetEmailIdentity`<br />`ses:DescribeReceiptRuleSet`<br />`ses:GetConfigurationSetEventDestinations`<br />`ses:GetConfigurationSet` | 
| 编辑电子邮件域和地址 | `ses:CreateReceiptRule`<br />`ses:UpdateReceiptRule`<br />`ses:SetActiveReceiptRuleSet`<br />`ses:CreateReceiptRuleSet`<br />`ses:CreateEmailIdentity`<br />`ses:TagResource`<br />`ses:UntagResource`<br />`ses:DeleteReceiptRule`<br />`ses:DeleteReceiptRuleSet`<br />`ses:CloneReceiptRuleSet`<br />`ses:CreateConfigurationSet`<br />`ses:CreateConfigurationSetEventDestination`<br />`ses:PutEmailIdentityConfigurationSetAttributes`<br />`ses:CreateEmailIdentityPolicy`<br />`ses:UpdateEmailIdentityPolicy`<br />`ses:DeleteEmailIdentityPolicy`<br />`iam:CreateServiceLinkedRole`<br />`iam:PassRole`<br />`iam:CreateRole`<br />`iam:CreatePolicy` | 

## “案例”页面
<a name="cases-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看案例域详细信息 | `connect:ListInstances`<br />`ds:DescribeDirectories`<br />`connect:ListIntegrationAssociations`<br />`cases:GetDomain` | 
| 加入 Cases | `connect:ListInstances`<br />`connect:ListIntegrationAssociations`<br />`cases:GetDomain`<br />`cases:CreateDomain`<br />`connect:CreateIntegrationAssociation`<br />`connect:DescribeInstance`<br />`iam:PutRolePolicy` | 

## 客户身份验证页面
<a name="customer-authentication-page"></a>


| 操作/使用案例 | 所需权限 | 
| --- | --- | 
| 查看客户身份验证 | `connect:ListIntegrationAssociations`<br />`cognito-idp:ListUserPools`<br />`cognito-idp:DescribeUserPool` | 
| 加入客户身份验证 | `connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`cognito-idp:ListUserPools`<br />`cognito-idp:DescribeUserPool`<br />`cognito-idp:ListUserPoolClients`<br />`cognito-idp:TagResource`<br />`cognito-idp:CreateUserPool` | 

## 出站活动页面
<a name="outbound-campaigns-page"></a>


|  操作/使用案例  |  所需权限  | 
| --- | --- | 
|  查看出站活动  | `connect:ListIntegrationAssociations`<br />`connect:ListPhoneNumbersV2`<br />`connect:SearchEmailAddresses`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`kms:DescribeKey`<br />`kms:ListKeys`<br />`profile:ListAccountIntegrations`<br />`profile:ListIntegrations`<br />`profile:ListDomains`<br />`profile:GetDomain`<br />`wisdom:ListKnowledgeBases`<br />`wisdom:GetKnowledgeBase`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:ListConnectInstanceIntegrations` | 
|  创建出站活动  | `connect-campaigns:StartInstanceOnboardingJob`<br />`connect-campaigns:DeleteInstanceOnboardingJob`<br />`connect-campaigns:GetConnectInstanceConfig`<br />`connect-campaigns:GetInstanceOnboardingJobStatus`<br />`connect-campaigns:DeleteConnectInstanceConfig`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`connect:UpdateInstanceAttribute`<br />`iam:CreateServiceLinkedRole`<br />`iam:DeleteServiceLinkedRole`<br />`iam:AttachRolePolicy`<br />`iam:PutRolePolicy`<br />`iam:DeleteRolePolicy`<br />`events:PutRule`<br />`events:PutTargets`<br />`events:DeleteRule`<br />`events:RemoveTargets`<br />`events:DescribeRule`<br />`events:ListTargetsByRule`<br />`ds:DescribeDirectories`<br />`kms:DescribeKey`<br />`kms:ListKeys`<br />`kms:CreateGrant`<br />`kms:RetireGrant`<br />`profile:CreateDomain`<br />`profile:ListAccountIntegrations`<br />`profile:ListIntegrations`<br />`profile:PutIntegration`<br />`profile:PutProfileObjectType`<br />`connect:CreateIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`connect:UpdateInstanceAttribute`<br />`connect:AssociateCustomerProfilesDomain`<br />`connect-campaigns:ListConnectInstanceIntegrations`<br />`connect-campaigns:PutConnectInstanceIntegration`<br />`wisdom:CreateKnowledgeBase`<br />`wisdom:ListKnowledgeBases` | 

## Connect 人工智能代理页面
<a name="wisdom-page"></a>


| 操作/使用案例 | 所需权限 | 
| --- | --- | 
| 查看域和集成 | `wisdom:ListAssistantAssociations`<br />`appflow:DescribeConnectorProfiles`<br />`app-integrations:GetDataIntegration`<br />`connect:DescribeInstance`<br />`connect:DescribeInstanceAttribute`<br />`connect:ListIntegrationAssociations`<br />`kms:DescribeKey`<br />`kms:ListGrants`<br />`wisdom:GetAssistant`<br />`wisdom:GetKnowledgeBase`<br />`wisdom:ListAssistantAssociations` | 
| 添加或删除域 | `connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`iam:DeleteRolePolicy`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:DescribeKey`<br />`kms:ListAliases`<br />`wisdom:CreateAssistant`<br />`wisdom:DeleteAssistant`<br />`wisdom:GetAssistant`<br />`wisdom:ListAssistantAssociations`<br />`wisdom:ListAssistants`<br />`wisdom:TagResource` | 
| 添加或删除集成 | `wisdom:ListAssistantAssociations`<br />`app-integrations:CreateDataIntegration`<br />`app-integrations:CreateDataIntegrationAssociation`<br />`app-integrations:DeleteDataIntegrationAssociation`<br />`app-integrations:GetDataIntegration`<br />`app-integrations:ListDataIntegrations`<br />`appflow:CreateConnectorProfile`<br />`appflow:CreateFlow`<br />`appflow:DeleteFlow`<br />`appflow:DescribeConnector`<br />`appflow:DescribeConnectorEntity`<br />`appflow:DescribeConnectorProfiles`<br />`appflow:DescribeConnectors`<br />`appflow:DescribeFlow`<br />`appflow:ListConnectorEntities`<br />`appflow:StartFlow`<br />`appflow:StopFlow`<br />`appflow:TagResource`<br />`appflow:UseConnectorProfile`<br />`connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`connect:ListIntegrationAssociations`<br />`iam:DeleteRolePolicy`<br />`iam:PutRolePolicy`<br />`kms:CreateGrant`<br />`kms:Decrypt`<br />`kms:DescribeKey`<br />`kms:GenerateDataKey`<br />`kms:ListAliases`<br />`kms:ListGrants`<br />`secretsmanager:CreateSecret`<br />`secretsmanager:PutResourcePolicy`<br />`wisdom:CreateAssistantAssociation`<br />`wisdom:CreateKnowledgeBase`<br />`wisdom:DeleteAssistantAssociation`<br />`wisdom:DeleteKnowledgeBase`<br />`wisdom:GetAssistant`<br />`wisdom:GetKnowledgeBase`<br />`wisdom:ListAssistantAssociations`<br />`wisdom:ListKnowledgeBases`<br />`wisdom:TagResource` | 

## “Voice ID”页面
<a name="voiceid-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看 Voice ID 集成 | `voiceid:DescribeDomain`<br />`voiceid:ListDomains`<br />`voiceid:RegisterComplianceConsent`<br />`voiceid:DescribeComplianceConsent`<br />`connect:ListIntegrationAssociations` | 
| 编辑 Voice ID 集成 | `voiceid:DescribeDomain`<br />`voiceid:ListDomains`<br />`voiceid:RegisterComplianceConsent`<br />`voiceid:DescribeComplianceConsent`<br />`voiceid:UpdateDomain`<br />`voiceid:CreateDomain`<br />`connect:ListIntegrationAssociations`<br />`connect:CreateIntegrationAssociation`<br />`connect:DeleteIntegrationAssociation`<br />`events:PutRule`<br />`events:DeleteRule`<br />`events:PutTargets`<br />`events:RemoveTargets`<br />`iam:PutRolePolicy` | 

## “预测、容量规划和调度”页面
<a name="forecasting-page"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 查看预测、容量规划和调度 | `connect:DescribeForecastingPlanningSchedulingIntegration` | 
| 启用预测、容量规划和调度 | `connect:UpdateInstanceAttribute`<br />`connect:StartForecastingPlanningSchedulingIntegration` | 
| 禁用预测、容量规划和调度 | `connect:UpdateInstanceAttribute`<br />`connect:StopForecastingPlanningSchedulingIntegration` | 

## 联合身份验证
<a name="federations"></a>

### SAML 联合身份验证
<a name="saml-federation"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| SAML 联合身份验证 | `connect:GetFederationToken` | 

### 管理员/紧急联合身份验证
<a name="admin-emergency-federation"></a>


| 操作/用例 | 所需权限 | 
| --- | --- | 
| 管理员/紧急联合身份验证 | `connect:AdminGetEmergencyAccessToken` | 