Plugin Actions
Amazon Q Business plugins let end users perform supported read and write operations in connected third-party services, such as creating a ServiceNow incident or a Salesforce case, from the Q Business chat interface.
Recorded characteristics
- Function
- Allows Amazon Q Business end users to perform supported operations in connected third-party services from the Q Business web experience chat, using built-in plugins (including Jira Cloud, Salesforce, ServiceNow, Zendesk Suite, Asana, Confluence, Google Calendar, Microsoft Exchange, Microsoft Teams, PagerDuty and Smartsheet) or custom plugins defined with an OpenAPI schema. When chat orchestration is enabled, Amazon Q Business can select the appropriate plugin automatically instead of requiring the user to choose plugin mode.
- Data access
- Access is bounded by the configured plugin, its supported operations, the authenticated OAuth connection to the third-party service and the end user's own authentication to that service. Documented operations vary by plugin: for example the Salesforce plugin manages cases (create, delete, update, get), retrieves account lists, handles opportunities and fetches contacts; the ServiceNow plugin creates, reads, updates and deletes incidents and change requests; the Jira Cloud plugin reads, creates, searches and deletes issues, changes issue status and manages sprints. AWS does not document unrestricted access to the connected systems.
- Actions
- Can take actions
- External actions
- Yes
- Human confirmation
- Required
- Permission basis
- User permissions
- Administrative control
- Administrators configure plugins in the Amazon Q Business console under Actions > Plugins, and can add, edit, activate, deactivate or delete them (up to 25 plugins per application environment). If a plugin is deactivated, end users do not see the option to use a plugin; when activated, all authorized end users can use it and per-user access cannot be customised. Chat orchestration is a separate admin global control that determines whether Amazon Q automatically routes chat requests across plugins and data sources or whether users must manually select plugin mode. Built-in plugins also require specified IAM permissions on the web experience role and an IAM service role granting access to the Secrets Manager secret holding the OAuth credentials.
- Default state
- Disabled
- Availability
- Documented as part of the Amazon Q Business service in supported AWS Regions. Current AWS documentation states that Amazon Q Business is no longer open to new customers and points prospective customers to Amazon Quick, so plugin actions remain documented for existing customers rather than newly available.
- Licensing
- Built-in plugins require an Amazon Q Business Pro subscription; AWS states built-in and custom plugins are not available with the Lite plan and users must upgrade to Pro. Index capacity and user subscriptions are charged separately.
- External model or provider
- Amazon Bedrock (Amazon Q Business is built on Amazon Bedrock; AWS does not name the specific model used for plugin action orchestration).
- Limitations and uncertainty
- AWS documents that write actions present a review form the user must submit, and that with chat orchestration Amazon Q presents forms for user validation of write actions; the precise behaviour of every orchestrated path is not exhaustively documented. Runtime permission enforcement is inferred from documented per-end-user OAuth authentication to the third-party service rather than an explicit AWS statement that actions are limited to the user's third-party privileges. Plugin operation sets differ per service and some legacy plugins support only a single create action. Amazon Q Business is closed to new customers, so future documentation changes may reflect migration to Amazon Quick rather than capability evolution.
Evidence
- Configuring actions in Amazon Q Business
Supports: Function · Actions · Admin controls · Availability · Limitations · Primary source
Plugins enable end users to perform specific tasks in third-party services from within their web experience chat.
Plugins let end users change the status of a ticket or view open incidents from chat.
Up to 25 plugins per application environment; plugins can be activated, deactivated, edited or deleted.
Amazon Q Business documentation states the service is no longer open to new customers and points to Amazon Quick.
A maximum of 25 plugins per application environment, each serving a different purpose.
- Built-in plugins for Amazon Q Business
Supports: Function · Actions · Data access · Limitations · Primary source
Built-in plugins exist for Jira Cloud, Salesforce, ServiceNow, Zendesk Suite and other services, each with a listed action set.
Documented actions include creating, updating and deleting Jira issues, ServiceNow incidents, Salesforce cases and Zendesk tickets.
Each plugin exposes a defined operation set bounding what data can be retrieved or modified.
Legacy Jira, Salesforce, ServiceNow and Zendesk plugins support only a single create action.
- Using Amazon Q Business built-in plugins
Supports: Function · External actions · Human confirmation · Admin controls · Default state · Primary source
After plugins are configured, users perform supported actions in the web experience chat via quick create or contextual create.
Example prompts include logging an incident in ServiceNow and creating a Salesforce case from chat.
Amazon Q displays a review form where the user fills in required information, and the action must be submitted to complete.
Deactivated plugins are not shown to end users; end-user access to plugins cannot be customised.
Plugins must be configured before use, and users only see the plugin option when a plugin is activated.
- Using a custom plugin in Amazon Q Business
Supports: Function · Human confirmation · Permission basis · Primary source
Custom plugins let users perform operations in any third-party application after authenticating.
For a write API operation, end users always get a confirmation form before the action is performed.
Each end user authenticates to the third-party application themselves the first time they use the plugin or when their login expires.
- Configuring a ServiceNow plugin for Amazon Q Business
Supports: Actions · External actions · Primary source
ServiceNow plugin supports create, read, update and delete of incidents and change requests.
Incidents and change requests are created directly in the connected ServiceNow instance.
- Configuring a Salesforce plugin for Amazon Q Business
Supports: Actions · External actions · Permission basis · Data access · Primary source
Salesforce plugin manages cases (create, delete, update, get) and opportunities.
Amazon Q Business executes case creation and updates against the customer's separate Salesforce instance via its domain URL and OAuth connection.
Plugin connections use OAuth 2.0 with a user redirect after authentication, with scoped permissions in the third-party application.
Salesforce plugin returns a maximum of five items per query and is scoped to the configured instance domain.
- Using global controls in Amazon Q Business
Supports: Human confirmation · Admin controls · Limitations · Primary source
Chat orchestration detects write actions and presents forms for user validation, validating actions before taking them.
Chat orchestration can be activated or deactivated as a global control, determining automatic plugin routing.
Chat orchestration is optimised for English content and disables hallucination mitigation when enabled.
- Prerequisites for configuring Amazon Q Business built-in plugins
Supports: Permission basis · Licensing · Primary source
The Amazon Q Business web experience IAM role requires specific plugin-related permissions in addition to third-party authentication.
Built-in plugins require an Amazon Q Business Pro subscription; Lite users cannot access plugin functionality.
- Managing Amazon Q Business plugins
Supports: Admin controls · Default state · Primary source
Administrators add, edit, activate, deactivate and delete plugins from the Amazon Q Business console.
Plugins are activated or deactivated explicitly by an administrator, with status shown as Active or Inactive.
- Subscription tiers and index types
Supports: Licensing · Primary source
Built-in and custom plugins are not available with the Lite plan.