AWS connect: Clarify download/delete wording for recording permissions
Summary
Removed the phrase 'and delete' from the description of recording download-button permissions, so the permission is described as enabling download only (deletion no longer implied).
Security assessment
The edit narrows the documented scope of a security-profile permission from 'download and delete' to 'download', reducing ambiguity about what access the permission grants. This is security-adjacent authorization documentation, not a fix for a specific vulnerability.
Evidence
-Recorded conversations - Enable download button | DownloadCallRecordings | Enables buttons on the Connect Customer admin website to download and delete call recordings. By default, the **Enable download button** permission is granted so they can [download call recordings](./download-recordings.html) through the Connect Customer admin website.
Diff
diff --git a/connect/latest/adminguide/security-profile-list.md b/connect/latest/adminguide/security-profile-list.md index c3e74d976..74d0971be 100644 --- a//connect/latest/adminguide/security-profile-list.md +++ b//connect/latest/adminguide/security-profile-list.md @@ -270 +270 @@ Automated interaction voice (IVR) recordings (unredacted) - Access | AutomatedV -Automated interaction voice (IVR) recordings (unredacted) - Enable download button | AutomatedVoiceInteraction.Recordings.Unredacted.DownloadButton | Enables buttons to download and delete call recordings. The **Enable download button** permission is selected by default when you select the **Automated interaction voice (IVR) recordings** permission so they can [download call recordings](./download-recordings.html) through the Connect Customer admin website. To perform a download, however, they need the **Automated interaction voice (IVR) recordings (unredacted) - Access** permission. +Automated interaction voice (IVR) recordings (unredacted) - Enable download button | AutomatedVoiceInteraction.Recordings.Unredacted.DownloadButton | Enables buttons to download call recordings. The **Enable download button** permission is selected by default when you select the **Automated interaction voice (IVR) recordings** permission so they can [download call recordings](./download-recordings.html) through the Connect Customer admin website. To perform a download, however, they need the **Automated interaction voice (IVR) recordings (unredacted) - Access** permission. @@ -319 +319 @@ You cannot access both the redacted and unredacted version of a conversation at -Recorded conversations - Enable download button | DownloadCallRecordings | Enables buttons on the Connect Customer admin website to download and delete call recordings. By default, the **Enable download button** permission is granted so they can [download call recordings](./download-recordings.html) through the Connect Customer admin website. To perform a download, however, they need permissions to access a **Recorded conversation (unredacted)**. +Recorded conversations - Enable download button | DownloadCallRecordings | Enables buttons on the Connect Customer admin website to download call recordings. By default, the **Enable download button** permission is granted so they can [download call recordings](./download-recordings.html) through the Connect Customer admin website. To perform a download, however, they need permissions to access a **Recorded conversation (unredacted)**.