Creates a security profile¶
Description¶
Creates a security profile.
For information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.
Usage¶
connect_create_security_profile(SecurityProfileName, Description,
Permissions, InstanceId, Tags, AllowedAccessControlTags,
TagRestrictedResources, Applications, HierarchyRestrictedResources,
AllowedAccessControlHierarchyGroupId, AllowedFlowModules,
AllowedAIAgents, GranularAccessControlConfiguration)
Arguments¶
-
SecurityProfileName[required] The name of the security profile.
-
DescriptionThe description of the security profile.
-
PermissionsPermissions assigned to the security profile. For a list of valid permissions, see List of security profile permissions.
-
InstanceId[required] The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.
-
TagsThe tags used to organize, track, or control access for this resource. For example, { "Tags": {"key1":"value1", "key2":"value2"} }.
-
AllowedAccessControlTagsThe list of tags that a security profile uses to restrict access to resources in Connect Customer.
-
TagRestrictedResourcesThe list of resources that a security profile applies tag restrictions to in Connect Customer. For a list of Connect Customer resources that you can tag, see Add tags to resources in Connect Customer in the Connect Customer Administrator Guide.
-
ApplicationsA list of third-party applications or MCP Servers that the security profile will give access to.
-
HierarchyRestrictedResourcesThe list of resources that a security profile applies hierarchy restrictions to in Connect Customer. Following are acceptable ResourceNames:
User. -
AllowedAccessControlHierarchyGroupIdThe identifier of the hierarchy group that a security profile uses to restrict access to resources in Connect Customer.
-
AllowedFlowModulesA list of Flow Modules an AI Agent can invoke as a tool.
-
AllowedAIAgentsA list of AI agents that the security profile will give access to.
-
GranularAccessControlConfigurationThe granular access control configuration for the security profile, including data table permissions.
Value¶
A list with the following syntax:
Request syntax¶
svc$create_security_profile(
SecurityProfileName = "string",
Description = "string",
Permissions = list(
"string"
),
InstanceId = "string",
Tags = list(
"string"
),
AllowedAccessControlTags = list(
"string"
),
TagRestrictedResources = list(
"string"
),
Applications = list(
list(
Namespace = "string",
ApplicationPermissions = list(
"string"
),
Type = "MCP"|"THIRD_PARTY_APPLICATION"
)
),
HierarchyRestrictedResources = list(
"string"
),
AllowedAccessControlHierarchyGroupId = "string",
AllowedFlowModules = list(
list(
Type = "MCP",
FlowModuleId = "string"
)
),
AllowedAIAgents = list(
list(
Arn = "string",
Type = "THIRD_PARTY"
)
),
GranularAccessControlConfiguration = list(
DataTableAccessControlConfiguration = list(
PrimaryAttributeAccessControlConfiguration = list(
PrimaryAttributeValues = list(
list(
AccessType = "ALLOW",
AttributeName = "string",
Values = list(
"string"
)
)
)
)
)
)
)