> ## Documentation Index
> Fetch the complete documentation index at: https://docs.operata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Contact Flow Log redaction

> Apply a redaction policy to the contact-flow log Lambda so PII is stripped from every CloudWatch event before it reaches Operata.

Configure the contact-flow log redaction Lambda to apply your rules to every event it reads from CloudWatch, shipping only the surviving payload to Operata.

## Before you start

* The [Contact Flow Logs collection](/docs/contact-flow-logs) stack deployed against your Amazon Connect instance.
* An Operata API token with admin permissions. See [Authentication](/docs/api-authentication).
* The list of Contact Flow Log field paths you want to allow, deny, encrypt, or transform. The schema and the mandatory keep-list live in [Contact Flow Log redaction schema](/docs/contact-flow-log-privacy).

<Warning>
  Today only the Mandatory tier is enforced end to end. Allow, Deny, Encrypt, and Transform rules are accepted in the config but applied as pass-through. Follow the [Operata changelog](/docs/changelog) for rollout.
</Warning>

## Steps

### 1. Draft your rules

Path notation is dot-delimited against the Contact Flow Log JSON payload. `Parameters` matches the entire object; `Parameters.CustomerCardNumber` matches one subfield. Rules apply at every depth.

Common drafts:

```json theme={null}
{
  "rules": [
    { "type": "DENY",    "field": "Parameters.CustomerCardNumber" },
    { "type": "ALLOW",   "field": "Parameters.Queue" },
    { "type": "ENCRYPT", "field": "Parameters.TextInput" }
  ]
}
```

Rules that target a mandatory field are rejected. See [Contact Flow Log redaction schema](/docs/contact-flow-log-privacy#mandatory-keep-list) for the full list.

### 2. Send the policy to Operata Support

The customer-facing API for Contact Flow Log redaction policies is not yet public. Send your drafted ruleset to [Operata Support](mailto:support@operata.com) with the Operata Group ID you want it applied to. Operata installs the policy against your Lambda and confirms when it is live.

### 3. Wait for the Lambda to pick up the new policy

The redaction Lambda reads the active policy on each invocation. Allow up to a minute for in-flight events to drain under the previous policy. The new policy has no effect on events the Lambda already collected — redaction runs at ingest time, not retroactively.

## Result

Place a test contact through the contact flow you instrumented, then read the matching contact back through the Operata API. Denied fields drop from the response, the mandatory keep-list survives, and every other field's value is `null` until Allow, Encrypt, and Transform reach end-to-end enforcement.

```bash theme={null}
curl -u "$OPERATA_GROUP_ID:$OPERATA_API_TOKEN" \
  "https://api.operata.io/v1/data/calls?fromTime=2026-05-18T00:00:00Z&toTime=2026-05-18T23:59:59Z&size=1"
```

## Related

* [Contact Flow Log redaction schema](/docs/contact-flow-log-privacy) — field tiers, mandatory keep-list, and processing order.
* [Privacy and redaction](/docs/concepts-privacy-and-redaction) — the cross-integration model.
* [Configure Lex redaction](/docs/guides-configure-lex-redaction) — the sibling rollout for Amazon Lex conversation logs.
