Skip to content

Creates a security profile

Description

Creates a security profile.

For information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

Usage

connect_create_security_profile(SecurityProfileName, Description,
  Permissions, InstanceId, Tags, AllowedAccessControlTags,
  TagRestrictedResources, Applications, HierarchyRestrictedResources,
  AllowedAccessControlHierarchyGroupId, AllowedFlowModules,
  AllowedAIAgents, GranularAccessControlConfiguration)

Arguments

  • SecurityProfileName

    [required] The name of the security profile.

  • Description

    The description of the security profile.

  • Permissions

    Permissions assigned to the security profile. For a list of valid permissions, see List of security profile permissions.

  • InstanceId

    [required] The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

  • Tags

    The tags used to organize, track, or control access for this resource. For example, { "Tags": {"key1":"value1", "key2":"value2"} }.

  • AllowedAccessControlTags

    The list of tags that a security profile uses to restrict access to resources in Connect Customer.

  • TagRestrictedResources

    The list of resources that a security profile applies tag restrictions to in Connect Customer. For a list of Connect Customer resources that you can tag, see Add tags to resources in Connect Customer in the Connect Customer Administrator Guide.

  • Applications

    A list of third-party applications or MCP Servers that the security profile will give access to.

  • HierarchyRestrictedResources

    The list of resources that a security profile applies hierarchy restrictions to in Connect Customer. Following are acceptable ResourceNames: User.

  • AllowedAccessControlHierarchyGroupId

    The identifier of the hierarchy group that a security profile uses to restrict access to resources in Connect Customer.

  • AllowedFlowModules

    A list of Flow Modules an AI Agent can invoke as a tool.

  • AllowedAIAgents

    A list of AI agents that the security profile will give access to.

  • GranularAccessControlConfiguration

    The granular access control configuration for the security profile, including data table permissions.

Value

A list with the following syntax:

list(
  SecurityProfileId = "string",
  SecurityProfileArn = "string"
)

Request syntax

svc$create_security_profile(
  SecurityProfileName = "string",
  Description = "string",
  Permissions = list(
    "string"
  ),
  InstanceId = "string",
  Tags = list(
    "string"
  ),
  AllowedAccessControlTags = list(
    "string"
  ),
  TagRestrictedResources = list(
    "string"
  ),
  Applications = list(
    list(
      Namespace = "string",
      ApplicationPermissions = list(
        "string"
      ),
      Type = "MCP"|"THIRD_PARTY_APPLICATION"
    )
  ),
  HierarchyRestrictedResources = list(
    "string"
  ),
  AllowedAccessControlHierarchyGroupId = "string",
  AllowedFlowModules = list(
    list(
      Type = "MCP",
      FlowModuleId = "string"
    )
  ),
  AllowedAIAgents = list(
    list(
      Arn = "string",
      Type = "THIRD_PARTY"
    )
  ),
  GranularAccessControlConfiguration = list(
    DataTableAccessControlConfiguration = list(
      PrimaryAttributeAccessControlConfiguration = list(
        PrimaryAttributeValues = list(
          list(
            AccessType = "ALLOW",
            AttributeName = "string",
            Values = list(
              "string"
            )
          )
        )
      )
    )
  )
)