Before you start
- The Contact Flow Logs collection stack deployed against your Amazon Connect instance.
- An Operata API token with admin permissions. See Authentication.
- The list of Contact Flow Log field paths you want to allow, deny, encrypt, or transform. The schema and the mandatory keep-list live in Contact Flow Log redaction schema.
Steps
1. Draft your rules
Path notation is dot-delimited against the Contact Flow Log JSON payload.Parameters matches the entire object; Parameters.CustomerCardNumber matches one subfield. Rules apply at every depth.
Common drafts:
2. Send the policy to Operata Support
The customer-facing API for Contact Flow Log redaction policies is not yet public. Send your drafted ruleset to Operata Support with the Operata Group ID you want it applied to. Operata installs the policy against your Lambda and confirms when it is live.3. Wait for the Lambda to pick up the new policy
The redaction Lambda reads the active policy on each invocation. Allow up to a minute for in-flight events to drain under the previous policy. The new policy has no effect on events the Lambda already collected — redaction runs at ingest time, not retroactively.Result
Place a test contact through the contact flow you instrumented, then read the matching contact back through the Operata API. Denied fields drop from the response, the mandatory keep-list survives, and every other field’s value isnull until Allow, Encrypt, and Transform reach end-to-end enforcement.
Related
- Contact Flow Log redaction schema — field tiers, mandatory keep-list, and processing order.
- Privacy and redaction — the cross-integration model.
- Configure Lex redaction — the sibling rollout for Amazon Lex conversation logs.