AWS Security ChangesHomeSearch

AWS connect: Document that archived flow modules still execute when referenced

Service: connect · 2026-09-27 · Documentation medium

File: connect/latest/adminguide/contact-flow-modules.md

Summary

Adds a new section explaining that flow modules do not honor archived/active lifecycle state during contact execution; archived modules continue to run if referenced by a flow, and manual removal from all flows is required to decommission them, with a recommendation to review referencing flows before archiving.

Security assessment

The change documents a lifecycle/behavior caveat: archived modules still execute, which could lead to unintended or stale logic running in contact flows. It is security-adjacent operational guidance (hardening/awareness) rather than a fix for a specific vulnerability, so it is not tied to a concrete incident.

Evidence

If a module is archived, it is still executed when referenced by a flow. To stop a module from being executed, you must remove it from all flows that reference it.

Diff

diff --git a/connect/latest/adminguide/contact-flow-modules.md b/connect/latest/adminguide/contact-flow-modules.md
index 70c196ea3..dd45aed66 100644
--- a//connect/latest/adminguide/contact-flow-modules.md
+++ b//connect/latest/adminguide/contact-flow-modules.md
@@ -65,0 +66,19 @@ For example, you want data that is written from Lambda (an External attribute) a
+### Flow modules: archived or active state
+
+###### Important
+
+Archived or active state is not supported for flow modules in contact execution. Unlike flows, modules do not honor the archived or active lifecycle state during contact execution.
+
+If a module is archived, it is still executed when referenced by a flow. To stop a module from being executed, you must remove it from all flows that reference it.
+
+Key details:
+
+  * Archived modules remain functional: An archived module continues to execute normally if it is invoked by an active flow.
+
+  * Manual removal required: To fully decommission a module, you must manually remove all references to it from any flows that use it. Archiving alone does not stop its execution.
+
+
+
+
+**Recommendation** : Before archiving a module, review all flows that reference it. Search your flows on the **Flows** page in the Connect Customer console to identify flows that call the module. If you intend to stop the module from executing, update or remove the module reference in each associated flow before archiving.
+