Amazon Web Services · Amazon Q Business

Plugin Actions

Amazon Q Business plugins let end users perform supported read and write operations in connected third-party services, such as creating a ServiceNow incident or a Salesforce case, from the Q Business chat interface.

Recorded characteristics

Function
Allows Amazon Q Business end users to perform supported operations in connected third-party services from the Q Business web experience chat, using built-in plugins (including Jira Cloud, Salesforce, ServiceNow, Zendesk Suite, Asana, Confluence, Google Calendar, Microsoft Exchange, Microsoft Teams, PagerDuty and Smartsheet) or custom plugins defined with an OpenAPI schema. When chat orchestration is enabled, Amazon Q Business can select the appropriate plugin automatically instead of requiring the user to choose plugin mode.
Data access
Access is bounded by the configured plugin, its supported operations, the authenticated OAuth connection to the third-party service and the end user's own authentication to that service. Documented operations vary by plugin: for example the Salesforce plugin manages cases (create, delete, update, get), retrieves account lists, handles opportunities and fetches contacts; the ServiceNow plugin creates, reads, updates and deletes incidents and change requests; the Jira Cloud plugin reads, creates, searches and deletes issues, changes issue status and manages sprints. AWS does not document unrestricted access to the connected systems.
Actions
Can take actions
External actions
Yes
Human confirmation
Required
Permission basis
User permissions
Administrative control
Administrators configure plugins in the Amazon Q Business console under Actions > Plugins, and can add, edit, activate, deactivate or delete them (up to 25 plugins per application environment). If a plugin is deactivated, end users do not see the option to use a plugin; when activated, all authorized end users can use it and per-user access cannot be customised. Chat orchestration is a separate admin global control that determines whether Amazon Q automatically routes chat requests across plugins and data sources or whether users must manually select plugin mode. Built-in plugins also require specified IAM permissions on the web experience role and an IAM service role granting access to the Secrets Manager secret holding the OAuth credentials.
Default state
Disabled
Availability
Documented as part of the Amazon Q Business service in supported AWS Regions. Current AWS documentation states that Amazon Q Business is no longer open to new customers and points prospective customers to Amazon Quick, so plugin actions remain documented for existing customers rather than newly available.
Licensing
Built-in plugins require an Amazon Q Business Pro subscription; AWS states built-in and custom plugins are not available with the Lite plan and users must upgrade to Pro. Index capacity and user subscriptions are charged separately.
External model or provider
Amazon Bedrock (Amazon Q Business is built on Amazon Bedrock; AWS does not name the specific model used for plugin action orchestration).
Limitations and uncertainty
AWS documents that write actions present a review form the user must submit, and that with chat orchestration Amazon Q presents forms for user validation of write actions; the precise behaviour of every orchestrated path is not exhaustively documented. Runtime permission enforcement is inferred from documented per-end-user OAuth authentication to the third-party service rather than an explicit AWS statement that actions are limited to the user's third-party privileges. Plugin operation sets differ per service and some legacy plugins support only a single create action. Amazon Q Business is closed to new customers, so future documentation changes may reflect migration to Amazon Quick rather than capability evolution.

Evidence