Amazon Q Enterprise is a generative synthetic intelligence (AI)-powered assistant designed to reinforce enterprise operations. It’s a totally managed service that helps present correct solutions to customers’ questions whereas honoring the safety and entry restrictions of the content material. It may be tailor-made to your particular enterprise wants by connecting to your organization’s info and enterprise methods utilizing built-in connectors to quite a lot of enterprise knowledge sources. Amazon Q Enterprise permits customers in numerous roles, akin to advertising and marketing managers, challenge managers, and gross sales representatives, to have tailor-made conversations, remedy enterprise issues, generate content material, take motion, and extra, by means of an online interface. This service goals to assist make workers work smarter, transfer sooner, and drive important impression by offering rapid and related info to assist them with their duties.
One such enterprise knowledge repository you should utilize to retailer content material is Atlassian Confluence. Confluence is a group workspace that gives a spot to create, and collaborate on numerous initiatives, merchandise, or concepts. Workforce areas assist your groups construction, manage, and share work, so every consumer has visibility into the institutional data of the enterprise and entry to the data they want or solutions to the questions they’ve.
There are two Confluence offerings:
- Cloud – That is provided as a software program as a service (SaaS) product. It’s at all times on and constantly up to date.
- Data Center (self-managed) – Right here, you host Confluence in your infrastructure, which can be on premises or the cloud, permitting you to maintain knowledge inside your chosen atmosphere and handle it your self.
Your customers could have to get solutions in Amazon Q Enterprise from the content material in Atlassian’s Confluence Cloud occasion as part of their work. For this you will want to configure an Amazon Q Confluence Cloud connector. As part of this configuration, one of many steps is to configure the authentication of the connector in order that it may possibly authenticate with Confluence (Cloud) after which index the related content material.
This publish covers the steps to configure the Confluence Cloud connector for Amazon Q Enterprise.
Kinds of paperwork
While you join Amazon Q to a knowledge supply, what Amazon Q considers—and crawls—as a doc varies by connector. The Confluence Cloud connector crawls the next as paperwork:
- Areas – Every area is taken into account a single doc.
- Pages – Every web page is taken into account a single doc.
- Blogs – Every weblog is taken into account a single doc.
- Feedback – Every remark is taken into account a single doc.
- Attachments – Every attachment is taken into account a single doc.
Metadata
Each doc has structural attributes—or metadata—hooked up to it. Doc attributes can embrace info akin to doc title, doc creator, time created, time up to date, and doc kind.
While you join Amazon Q Enterprise to a knowledge supply, it mechanically maps particular knowledge supply doc attributes to fields inside an Amazon Q Enterprise index. If a doc attribute in your knowledge supply doesn’t have an attribute mapping already out there, or if you wish to map further doc attributes to index fields, use the {custom} area mappings to specify how a knowledge supply attribute maps to an Amazon Q Enterprise index area. You create area mappings by enhancing your knowledge supply after your utility and retriever are created.
To be taught extra concerning the supported entities and the related reserved and {custom} attributes for the Amazon Q Confluence connector, check with Amazon Q Enterprise Confluence (Cloud) knowledge supply connector area mappings.
Authentication varieties
An Amazon Q Enterprise utility requires you to make use of AWS IAM Identification Heart to handle consumer entry. Though it’s really useful to have an IAM Identification Heart occasion configured (with customers federated and teams added) earlier than you begin, it’s also possible to select to create and configure an IAM Identification Heart occasion to your Amazon Q Enterprise utility utilizing the Amazon Q console.
You too can add customers to your IAM Identification Heart occasion from the Amazon Q Enterprise console, if you happen to aren’t federating identification. While you add a brand new consumer, make it possible for the consumer is enabled in your IAM Identification Heart occasion and so they have verified their e mail ID. They should full these steps earlier than they’ll log in to your Amazon Q Enterprise internet expertise.
Your identification supply in IAM Identification Heart defines the place your customers and teams are managed. After you configure your identification supply, you’ll be able to search for customers or teams to grant them single sign-on entry to AWS accounts, purposes, or each.
You’ll be able to have just one identification supply per group in AWS Organizations. You’ll be able to select one of many following as your identification supply:
- IAM Identification Heart listing – While you allow IAM Identification Heart for the primary time, it’s mechanically configured with an IAM Identification Heart listing as your default identification supply. That is the place you create your customers and teams, and assign their degree of entry to your AWS accounts and purposes.
- Energetic Listing – Select this feature if you wish to proceed managing customers in both your AWS Managed Microsoft AD listing utilizing AWS Listing Service or your self-managed listing in Energetic Listing (AD).
- Exterior Identification Supplier – Select this feature if you wish to handle customers in different exterior identification suppliers (IdPs) by means of the Safety Assertion Markup Language (SAML) 2.0 commonplace, akin to Okta.
Entry management lists
Amazon Q Enterprise connectors index entry management record (ACL) info that’s hooked up to a Confluence doc together with the doc itself. For doc ACLs, Amazon Q Enterprise indexes the next:
- Person e mail deal with
- Group title for the native group
- Group title for the federated group
While you join a Confluence (Cloud) knowledge supply to Amazon Q Enterprise, the connector crawls ACL (consumer and group) info hooked up to a doc out of your Confluence (Cloud) occasion. The knowledge is used to find out which content material can be utilized to assemble chat responses for a given consumer, in accordance the end-user’s doc entry permissions.
You configure consumer and group entry to Confluence areas utilizing the area permissions web page, in Confluence. Equally for pages and blogs, you utilize the restrictions web page. For extra details about area permissions, see Space Permissions Overview on the Confluence Assist web site. For extra details about web page and weblog restrictions, see Page Restrictions on the Confluence Assist web site.
An Amazon Q Enterprise connector updates any adjustments in ACLs every time that your knowledge supply content material is crawled. To seize ACL adjustments to make it possible for the best end-users have entry to the best content material, re-sync your knowledge supply repeatedly.
Identification crawling for Amazon Q Enterprise Person Retailer
As said earlier, Amazon Q Enterprise crawls ACL info on the doc degree from supported knowledge sources. As well as, Amazon Q Enterprise crawls and shops principal info inside every knowledge supply (native consumer alias, native group, and federated group identification configurations) into the Amazon Q Enterprise Person Retailer. That is helpful when your utility is linked to a number of knowledge sources with completely different authorization and authentication methods, however you wish to create a unified, access-controlled chat expertise to your end-users.
Amazon Q Enterprise internally maps the native consumer and group IDs hooked up to the doc, to the federated identities of customers and teams. Mapping identities streamlines consumer administration and accelerates chat responses by decreasing ACL info retrieval time throughout chat requests. Identification crawling, together with the authorization function, helps filter and generate internet expertise content material restricted by end-user context. For extra details about this course of, see Understanding Amazon Q Enterprise Person Retailer.
The group and consumer IDs are mapped as follows:
- _group_ids – Group names are current on areas, pages, and blogs the place there are restrictions. They’re mapped from the title of the group in Confluence. Group names are at all times lowercase.
- _user_id – Usernames are current on the area, web page, or weblog the place there are restrictions. They’re mapped relying on the kind of Confluence occasion that you just’re utilizing. For Confluence Cloud, the _user_id is the account ID of the consumer.
Overview of resolution
With Amazon Q Enterprise, you’ll be able to configure a number of knowledge sources to offer a central place to go looking throughout your doc repository. For our resolution, we show methods to index a Confluence repository utilizing the Amazon Q Enterprise connector for Confluence. On this weblog we are going to:
- Configure an Amazon Q Enterprise Software.
- Join Confluence (Cloud) to Amazon Q Enterprise.
- Index the information within the Confluence repository.
- Run a pattern question to check the answer.
Conditions
Earlier than you start utilizing Amazon Q Enterprise for the primary time, full the next duties:
- Arrange your AWS account.
- Optionally, set up the AWS Command Line Interface (AWS CLI).
- Optionally, arrange the AWS SDKs.
- Take into account AWS Areas and endpoints.
- Arrange required permissions.
- Allow and configure an IAM Identification Heart occasion.
For extra info, see Organising for Amazon Q Enterprise.
To arrange the Amazon Q Enterprise connector for Confluence, you have to full further conditions. For extra info, see Conditions for connecting Amazon Q Enterprise to Confluence (Cloud).
Create an Amazon Q Enterprise utility with the Confluence Cloud connector
As step one in the direction of making a generative AI assistant, you configure an utility. Then you choose and create a retriever, and likewise join any knowledge sources. After this, you grant end-user entry to customers to work together with an utility utilizing the popular identification supplier, IAM Identification Heart. Full the next steps:
- On the Amazon Q Enterprise console, select Get began.
Determine 1: Preliminary Amazon Q for Enterprise residence web page
- On the Purposes web page, select Create utility.
Determine 2: Amazon Q for Enterprise utility creation web page
- Enter a reputation to your utility, choose the extent of service entry, and connect with IAM Identification Heart. (Be aware: The IAM Identification Heart occasion doesn’t need to be in the identical Area as Amazon Q Enterprise.)
- Select Create.
Determine 3: Amazon Q for Enterprise utility configuration web page
For added particulars on configuring the Amazon Q utility and connecting to IAM Identification Heart, check with Creating an Amazon Q Enterprise utility atmosphere.
- Choose your retriever and index provisioning choices.
- Select Subsequent.
Determine 4: Amazon Q for Enterprise retriever choice web page
For added particulars on creating and choosing a retriever, check with Creating and choosing a retriever for an Amazon Q Enterprise utility.
- Hook up with Confluence as your knowledge supply.
- Enter a reputation and outline.
- Choose Confluence Cloud because the supply and enter your Confluence URL.
Determine 5: Confluence connector web page
- There are two choices for Authentication: Primary authentication and OAuth 2.0 authentication. Choose the most suitable choice relying in your use case.
Determine 6: Confluence connector authentication choices
Earlier than you join Confluence (Cloud) to Amazon Q Enterprise, you have to create and retrieve the Confluence (Cloud) credentials you’ll use to attach Confluence (Cloud) to Amazon Q Enterprise. You additionally want so as to add any permissions wanted by Confluence (Cloud) to connect with Amazon Q Enterprise.
The next procedures provide you with an summary of methods to configure Confluence (Cloud) to connect with Amazon Q Enterprise utilizing both fundamental authentication or OAuth 2.0 authentication.
Configure Confluence (Cloud) fundamental authentication for Amazon Q Enterprise
Full the next steps to configure fundamental authentication:
- Log in to your account from Confluence (Cloud). Be aware the username you logged in with. You will want this later to connect with Amazon Q Enterprise.
- Out of your Confluence (Cloud) residence web page, word your Confluence (Cloud) URL out of your Confluence browser URL. For instance, https://instance.atlassian.web. You will want this later to connect with Amazon Q Enterprise.
- Navigate to the Security web page in Confluence (Cloud).
- On the API tokens web page, select Create API token.
Determine 7: Confluence API token creation
- Within the Create an API token dialog field, for Label, add a reputation to your API token.
- Select Create.
Determine 8: Confluence API token labelling
- From the Your new API token dialog field, copy the API token and reserve it in your most well-liked textual content editor. You’ll be able to’t retrieve the API token after you shut the dialog field.
Determine 9: Copying your Confluence API token
- Select Shut.
You now have the username, Confluence (Cloud) URL, and Confluence (Cloud) API token you have to connect with Amazon Q Enterprise with fundamental authentication.
For extra info, see Manage API tokens for your Atlassian account in Atlassian Assist.
Configure Confluence (Cloud) OAuth 2.0 authentication for Amazon Q Enterprise
Full the next steps to configure Confluence (Cloud) OAuth 2.0 authentication:
- Retrieve the username and Confluence (Cloud) URL.
- Configure an OAuth 2.0 app integration.
- Retrieve the Confluence (Cloud) consumer ID and consumer secret.
- Generate a Confluence (Cloud) entry token.
- Generate a Confluence (Cloud) refresh token.
- Generate a brand new Confluence (Cloud) entry token utilizing a refresh token.
Retrieve the username and Confluence (Cloud) URL
Full the next steps:
- Log in to your account from Confluence (Cloud). Be aware the username you logged in with. You will want this later to connect with Amazon Q Enterprise.
- Out of your Confluence (Cloud) residence web page, word your Confluence (Cloud) URL out of your Confluence browser URL. For instance, https://instance.atlassian.web. You will want this later to each configure your OAuth 2.0 token and connect with Amazon Q Enterprise.
Configuring an OAuth 2.0 app integration
Full the next steps:
- Log in to your account from the Atlassian Developer page.
- Select the profile icon within the top-right nook and on the dropdown menu, select Developer console.
Determine 10: Logging into the Confluence Developer Console
- On the welcome web page, select Create and select OAuth 2.0 integration.
Determine 11: Creating your Confluence OAuth 2.0 token
- Below Create a brand new OAuth 2.0 (3LO) integration, for Title, enter a reputation for the OAuth 2.0 utility you’re creating. Then, learn the Developer Phrases, and choose I conform to be sure by Atlassian’s developer phrases checkbox, if you happen to do.
- Choose Create.
Determine 12: Creating your Confluence OAuth 2.0 integration
The console will show a abstract web page outlining the small print of the OAuth 2.0 app you created.
Determine 13: Your Confluence utility
- Nonetheless within the Confluence console, within the navigation pane, select Authorization.
- Select Add so as to add OAuth 2.0 (3LO) to your app.
Determine 14: Including OAuth 2.0 to your Confluence app
- Below OAuth 2.0 authorization code grants (3LO) for apps, for Callback URL, enter the Confluence (Cloud) URL you copied, then select Save adjustments.
Determine 15: Including OAuth 2.0 to your Confluence app (half 2)
- Below Authorization URL generator, select Add APIs so as to add APIs to your app. This can redirect you to the Permissions web page.
- On the Permissions web page, for Scopes, navigate to Person Identification API. Choose Add, then choose Configure.
Determine 16: Configuring Permissions to your Confluence app
- Below Person Identification API, select Edit Scopes, then add the next learn scopes:
- learn:me – View lively consumer profile.
- learn:account – View consumer profiles.
Determine 17: Configuring Scopes to your Confluence app
- Select Save and return to the Permissions web page.
- On the Permissions web page, for Scopes, navigate to Confluence API. Choose Add, after which choose Configure.
Determine 18: Configuring Permissions to your Confluence app (half 2)
- Below Confluence API, be sure you’re on the Basic scopes tab.
Determine 19: Configuring Permissions to your Confluence app (half 3)
- Select Edit Scopes and add the next learn scopes:
- learn:confluence-space.abstract – Learn Confluence area abstract.
- learn:confluence-props – Learn Confluence content material properties.
- learn:confluence-content.all – Learn Confluence detailed content material.
- learn:confluence-content.abstract – Learn Confluence content material abstract.
- learn:confluence-content.permission – Learn content material permission in Confluence.
- learn:confluence-user – Learn consumer.
- learn:confluence-groups – Learn consumer teams.
- Select Save.
- Navigate to the Granular scopes
Determine 20: Configuring Permissions to your Confluence app (half 4)
- Select Edit Scopes and add the next learn scopes:
- learn:content material:confluence – View detailed contents.
- learn:content-details:confluence – View content material particulars.
- learn:space-details:confluence – View area particulars.
- learn:audit-log:confluence – View audit data.
- learn:web page:confluence – View pages.
- learn:attachment:confluence – View and obtain content material attachments.
- learn:blogpost:confluence – View weblog posts.
- learn:custom-content:confluence – View {custom} content material.
- learn:remark:confluence – View feedback.
- learn:template:confluence – View content material templates.
- learn:label:confluence – View labels.
- learn:watcher:confluence – View content material watchers.
- learn:group:confluence – View teams.
- learn:relation:confluence – View entity relationships.
- learn:consumer:confluence – View consumer particulars.
- learn:configuration:confluence – View Confluence settings.
- learn:area:confluence – View area particulars.
- learn:area.permission:confluence – View area permissions.
- learn:area.property:confluence – View area properties.
- learn:consumer.property:confluence – View consumer properties.
- learn:area.setting:confluence – View area settings.
- learn:analytics.content material:confluence – View analytics for content material.
- learn:content material.permission:confluence – Verify content material permissions.
- learn:content material.property:confluence – View content material properties.
- learn:content material.restriction:confluence – View content material restrictions.
- learn:content material.metadata:confluence – View content material summaries.
- learn:inlinetask:confluence – View duties.
- learn:process:confluence – View duties.
- learn:permission:confluence – View content material restrictions and area permissions.
- learn:whiteboard:confluence – View whiteboards.
- learn:app-data:confluence – Learn app knowledge.
For extra info, see Implementing OAuth 2.0 (3LO) and Determining the scopes required for an operation in Atlassian Developer.
Retrieve the Confluence (Cloud) consumer ID and consumer secret
Full the next steps:
- Within the navigation pane, select Settings.
- Within the Authentication particulars part, copy and save the next in your most well-liked textual content editor:
- Shopper ID – You enter this because the app key on the Amazon Q Enterprise console.
- Secret – You enter this because the app secret on the Amazon Q Enterprise console.
Determine 21: Retrieving Confluence app authentication particulars
You want these to generate your Confluence (Cloud) OAuth 2.0 token and likewise to attach Amazon Q Enterprise to Confluence (Cloud).
For extra info, see Implementing OAuth 2.0 (3LO) and Determining the scopes required for an operation within the Atlassian Developer documentation.
Generate a Confluence (Cloud) entry token
Full the next steps:
- Log in to your Confluence account from the Atlassian Developer page.
- Open the OAuth 2.0 app you wish to generate a refresh token for.
- Within the navigation pane, select Authorization.
- For OAuth 2.0 (3LO), select Configure.
- On the Authorization web page, underneath Authorization URL generator, copy the URL for Granular Confluence API authorization URL and reserve it in your most well-liked textual content editor.
Determine 22: Retrieving Confluence API URL particulars
The URL is within the following format:
- Within the saved authorization URL, replace the state=${YOUR_USER_BOUND_VALUE} parameter worth to any textual content of your alternative. For instance, state=sample_text.
For extra info, see What is the state parameter used for? within the Atlassian Assist documentation.
- Open your most well-liked internet browser and enter the authorization URL you copied into the browser URL.
- On the web page that opens, be certain that all the things is appropriate and select Settle for.
Determine 23: Testing a Confluence API URL
You may be returned to your Confluence (Cloud) residence web page.
- Copy the URL of the Confluence (Cloud) residence web page and reserve it in your most well-liked textual content editor.
The URL incorporates the authorization code to your utility. You will want this code to generate your Confluence (Cloud) entry token. The entire part after code= is the authorization code.
- Navigate to Postman.
In case you don’t have Postman put in in your native system, it’s also possible to select to make use of cURL to generate a Confluence (Cloud) entry token. Use the next cURL command to take action:
- If, nonetheless, you will have Postman put in, on the primary Postman window, select POST as the strategy, then enter the next URL: https://auth.atlassian.com/oauth/token.
- Select Physique, then select uncooked and JSON.
Determine 24: Testing a Confluence entry token in Postman
- Within the textual content field, enter the next code extract, changing the fields along with your credential values:
- Select Ship.
If all the things is configured appropriately, Postman will return an entry token.
- Copy the entry token and reserve it in your most well-liked textual content editor. You will want it to attach Confluence (Cloud) to Amazon Q Enterprise.
For extra info, see Implementing OAuth 2.0 (3LO) within the Atlassian Developer documentation.
Generate a Confluence (Cloud) refresh token
The entry token you utilize to attach Confluence (Cloud) to Amazon Q Enterprise utilizing OAuth 2.0 authentication expires after 1 hour. When it expires, you’ll be able to both repeat the entire authorization course of and generate a brand new entry token, or generate a refresh token.
Refresh tokens are carried out utilizing a rotating refresh token mechanism. Every time they’re used, rotating refresh tokens points a brand new limited-life refresh token that’s legitimate for 90 days. Every new rotating refresh token resets the inactivity expiry time and allocates one other 90 days. This mechanism improves on single persistent refresh tokens by decreasing the interval wherein a refresh token could be compromised and used to acquire a sound entry token. For added particulars, see OAuth 2.0 (3LO) apps within the Atlassian Developer documentation.
To generate a refresh token, you add a %20offline_access parameter to the tip of the scope worth within the authorization URL you used to generate your entry token. Full the next steps to generate a refresh token:
- Log in to your account from the Atlassian Developer page.
- Open the OAuth 2.0 app you wish to generate a refresh token for.
- Within the navigation pane, select Authorization.
- For OAuth 2.0 (3LO), select Configure.
- On the Authorization web page, underneath Authorization URL generator, copy the URL for Granular Confluence API authorization URL and reserve it in your most well-liked textual content editor.
Determine 25: Retrieving Confluence API URL particulars
- Within the saved authorization URL, replace the state=${YOUR_USER_BOUND_VALUE} parameter worth to any textual content of your alternative. For instance, state=sample_text.
For extra info, see What is the state parameter used for? within the Atlassian Assist documentation.
- Add the next textual content on the finish of the scope worth in your authorization URL: %20offline_access and replica it. For instance:
- Open your most well-liked internet browser and enter the modified authorization URL you copied into the browser URL.
- On the web page that opens, be certain that all the things is appropriate after which select Settle for.
Determine 26: Testing a Confluence API URL
You may be returned to the Confluence (Cloud) console.
- Copy the URL of the Confluence (Cloud) residence web page and reserve it in a textual content editor of your alternative.
The URL incorporates the authorization code to your utility. You will want this code to generate your Confluence (Cloud) refresh token. The entire part after code= is the authorization code.
- Navigate to Postman.
In case you don’t have Postman put in in your native system, it’s also possible to select to make use of cURL to generate a Confluence (Cloud) entry token. Use the next cURL command to take action:
- If, nonetheless, you will have Postman put in, on the primary Postman window, select POST as the strategy, then enter the next URL: https://auth.atlassian.com/oauth/token.
- Select Physique on the menu, then select uncooked and JSON.
Determine 27: Retrieving a Confluence refresh token in Postman
- Within the textual content field, enter the next code extract, changing the fields along with your credential values:
- Select Ship.
If all the things is configured appropriately, Postman will return a refresh token.
- Copy the refresh token and reserve it utilizing your most well-liked textual content editor. You will want it to attach Confluence (Cloud) to Amazon Q Enterprise.
For extra info, see Implementing a Refresh Token Flow within the Atlassian Developer documentation.
Generate a brand new Confluence (Cloud) entry token utilizing a refresh token
You need to use the refresh token you generated to create a brand new entry token and refresh token pair when an current entry token expires. Full the next steps to generate a refresh token:
- Copy the refresh token you generated following the steps within the earlier part.
- Navigate to Postman.
In case you don’t have Postman put in in your native system, it’s also possible to select to make use of cURL to generate a Confluence (Cloud) entry token. Use the next cURL command to take action:
- Within the Postman foremost window, select POST as the strategy, then enter the next URL: https://auth.atlassian.com/oauth/token.
- Select Physique from the menu and select uncooked and JSON.
Determine 28: Utilizing a Confluence refresh token in Postman
- Within the textual content field, enter the next code extract, changing the fields along with your credential values:
- Select Ship.
If all the things is configured appropriately, Postman will return a brand new entry token and refresh token pair within the following format:



Tyler Geary is a Options Architect at Amazon Internet Providers (AWS), the place he’s a member of the Enterprise Monetary Providers group, specializing in Insurance coverage clients. He helps his clients determine enterprise challenges and alternatives, tying them again to modern options powered by AWS, with a specific give attention to Generative AI. In his free time, Tyler enjoys climbing, tenting, and spending time within the nice outdoor.
Sumeet Tripathi is an Enterprise Assist Lead (TAM) at AWS in North Carolina. He has over 17 years of expertise in expertise throughout numerous roles. He’s keen about serving to clients to scale back operational challenges and friction. His focus space is AI/ML and Vitality & Utilities Phase. Exterior work, He enjoys touring with household, watching cricket and films.
Vishal Naik is a Sr. Options Architect at Amazon Internet Providers (AWS). He’s a builder who enjoys serving to clients accomplish their enterprise wants and remedy advanced challenges with AWS options and greatest practices. His core space of focus consists of Generative AI and Machine Studying. In his spare time, Vishal loves making quick movies on time journey and alternate universe themes.