One of the most common surprises on a first Amazon Connect project is realising how much sits around Connect rather than inside it. Connect gives you telephony, routing, flows, and the agent workspace — but a production contact centre also needs physical kit for agents, a way to manage the platform as code, a release pipeline, secure payment handling, integrations into your other systems, and the project tooling to run it all. This is the full list, grouped by category, with a note on when each item is actually needed versus optional.
This is the "what to buy and build" companion to our Amazon Connect Jira backlog (the what to do) and roles & responsibilities guide (the who does it). Together the three cover the products, the work, and the team.
1. Agent-Side Hardware & Desktop
Agents need something to talk through and something to work in. Both are easy to under-budget for.
Headsets (e.g. Jabra, Poly, EPOS)
The single most impactful piece of agent hardware. Because Amazon Connect runs through a browser-based softphone, call quality depends heavily on the headset and its noise cancellation rather than on any desk phone. Jabra (e.g. the Engage and Evolve ranges), Poly, and EPOS are the brands most commonly specified for Connect deployments.
When you need it: always, for every voice agent. Specify USB (not just Bluetooth) for reliability, and certified noise-cancelling models for busy or home-office environments. Budget one per agent plus spares.
Agent workstation & a supported browser
Each agent needs a reasonably specced computer and a current, supported web browser — the Contact Control Panel and agent workspace are web applications, so there's no thick-client install, but an underpowered machine or outdated browser causes audio and UI problems.
When you need it: always. Confirm the machine meets the softphone's network and CPU expectations; run a network quality check for home workers.
The agent desktop
Where the agent actually works. You have three broad options: (1) the out-of-the-box Amazon Connect agent workspace (CCP, Customer Profiles, Cases, step-by-step guides, agent assist in one screen); (2) an embedded CCP inside your CRM or a custom app via the Amazon Connect Streams API; or (3) a partner/ISV agent desktop. Which you choose shapes a surprising amount of the rest of the project.
When you need it: always — the only question is which of the three. Start with the native workspace unless you have a strong reason to embed or build.
2. Development, Infrastructure-as-Code & CI/CD
You can click a contact centre together in the console, but you shouldn't run one that way. Treating Connect as code is what makes it repeatable, reviewable, and recoverable.
Terraform (or CloudFormation / AWS CDK)
Infrastructure-as-code for the Connect instance and its surrounding AWS resources. Terraform is the most common choice and has an AWS provider with resources for Connect instances, hours of operation, queues, routing profiles, Lambda functions, and more. CloudFormation and the AWS CDK are the native alternatives. Whichever you pick, the goal is the same: no "mystery config" that only exists because someone clicked it once.
When you need it: any project beyond a throwaway pilot. Essential for multiple environments (dev/test/prod) and disaster recovery.
A CI/CD pipeline
Automates building, testing, and promoting changes across environments rather than hand-copying flows between accounts. Common stacks are AWS CodePipeline / CodeBuild, GitHub Actions, or GitLab CI. The pipeline typically runs your Terraform/CloudFormation, deploys Lambda code, imports contact flows, and runs automated tests before promoting to production. For agentic (ACXD) builds there's a dedicated SDK-driven approach too.
When you need it: as soon as you have more than one environment or more than one developer. Covered in depth in our CI/CD pipeline guide and ACXD CI/CD article.
Source control & the AWS CLI / SDKs
A Git repository (GitHub, GitLab, CodeCommit) for flows-as-exports, Lambda code, IaC, prompts, and guardrail definitions; plus the AWS CLI and relevant SDKs for scripting and local development. The Amazon Connect Streams and Chat SDKs come in here too if you're embedding or building a custom desktop.
When you need it: always. Version-control everything you can export, including contact flows and Lambda.
AWS Lambda, API Gateway & a data store
Almost every non-trivial flow calls out to AWS Lambda for business logic (account lookups, validation, writing back to systems of record), often fronted by API Gateway, with data in DynamoDB or an existing database. These aren't optional extras so much as the standard integration backbone of a Connect build.
When you need it: as soon as a flow needs to know anything about the customer or take any action in another system — i.e. nearly always.
3. PCI-Compliant Payment Handling
If customers ever read out card details to an agent or into the IVR, you are in PCI DSS scope — and that is not something to improvise.
A PCI payment module (DTMF capture / pause-and-resume)
A dedicated payment capability keeps card data out of your contact centre's scope. The two common patterns are secure DTMF capture (the customer keys their card number on the phone keypad, with the digits masked and never reaching the agent or the call recording) and pause-and-resume recording (recording stops during card entry). These are typically delivered by a specialist AWS Partner payment solution integrated with Connect, or a validated third-party service, rather than built from scratch.
When you need it: any time payments are taken by phone. Treat this as a specialist procurement with security/compliance sign-off, not a developer task.
Don't DIY PCI. Rolling your own card capture is the fastest way to drag your whole AWS account into PCI audit scope. Use a validated payment module from an AWS Partner or qualified provider, and get your security & compliance architect to sign off the scope boundary before go-live.
4. Integration & CTI Tooling
A contact centre that can't see your other systems is just a phone line. Integration is where most of the value — and most of the build effort — actually lives.
CRM / CTI connector (Salesforce, ServiceNow, Zendesk, Dynamics)
Connects the agent desktop to your system of record so the right customer record screen-pops on answer, and interactions log back automatically. AWS and partners provide prebuilt CTI adapters/connectors for the major CRMs; a custom integration via Streams is the alternative where no connector fits.
When you need it: whenever agents use a CRM — which is almost always. This is frequently the biggest single integration workstream on the project.
Conversational AI: Amazon Lex or Agentic CX Designer (ACXD)
For natural-language IVR and self-service, you'll build on Amazon Lex (intent/slot bots) or the newer Agentic CX Designer (ACXD) for agentic, task-completing conversational applications. This is a product choice with real downstream consequences for how you design, test, and govern self-service.
When you need it: whenever self-service goes beyond simple press-1 menus. See our deterministic-to-agentic guide.
Knowledge base & customer data sources
Agent assist and self-service are only as good as what they can draw on: a connected knowledge base for answers, and Customer Profiles data unified from your CRM and other sources. Both need source systems identified, connected, and kept current.
When you need it: for any AI-assisted self-service or agent assist. See knowledge base integration options.
5. Monitoring, QA & Testing
You need to know the contact centre is healthy, that agents are performing, and that changes don't break things before customers find out.
Analytics & monitoring (CloudWatch, Contact Lens, dashboards)
Amazon CloudWatch for platform health and alarms; Contact Lens for conversational analytics, sentiment, and transcription; plus real-time and historical dashboards (native, Amazon QuickSight, or your BI tool of choice) for operational reporting.
When you need it: before go-live, not after. Flying blind on a live contact centre is how small problems become reputational ones.
Automated testing & eval tooling
Automated flow testing and load testing for the IVR, plus, for any AI self-service, an eval set and grading harness to catch regressions before they ship. This is the quality gate that lets your CI/CD pipeline promote with confidence.
When you need it: alongside the pipeline. See how to build an eval set and using evals to deliver excellence.
Call recording & storage (Amazon S3)
Connect stores recordings, transcripts, and exported data in Amazon S3. You'll need buckets configured with the right encryption, lifecycle, and retention policies — a small but genuinely required piece that intersects with both compliance and cost.
When you need it: always, if you record. Set retention and encryption deliberately rather than by default.
6. Project & Collaboration Tooling
Not glamorous, but a Connect project without clear backlog and documentation tooling drifts quickly.
Backlog & documentation tools (Jira, Confluence, etc.)
A backlog tool (Jira or equivalent) to run the implementation as sprints, and a documentation space (Confluence, SharePoint, a wiki) for the solution design, runbooks, call flow documentation, and the artifacts an agentic build needs. We have a ready-made Jira backlog you can import as a starting point.
When you need it: from day one. Agentic self-service in particular needs living documentation — see documenting agentic experiences.
The One-Page Checklist
| Item | Category | Needed? |
|---|---|---|
| Headsets (Jabra / Poly / EPOS) | Agent hardware | Always (per voice agent) |
| Agent workstation + supported browser | Agent hardware | Always |
| Agent desktop (native workspace / embedded CCP / partner) | Agent software | Always — pick one |
| Terraform / CloudFormation / CDK | Infrastructure-as-code | Any real project |
| CI/CD pipeline | Dev tooling | Multi-env / multi-dev |
| Source control + AWS CLI/SDKs | Dev tooling | Always |
| Lambda + API Gateway + data store | Integration backbone | Nearly always |
| PCI payment module (DTMF / pause-resume) | Compliance | If taking phone payments |
| CRM / CTI connector | Integration | If agents use a CRM |
| Amazon Lex / ACXD | Conversational AI | For NL self-service |
| Knowledge base + Customer Profiles sources | Integration | For AI assist / self-service |
| CloudWatch + Contact Lens + dashboards | Monitoring | Before go-live |
| Automated testing + eval tooling | QA | With the pipeline |
| S3 for recordings/storage | Operations | If recording |
| Jira / Confluence (backlog + docs) | Project | From day one |
How to use this list: walk it top to bottom in discovery and mark each item in scope / out of scope / TBD. The three that most often get missed until late — and cause the most pain — are the PCI payment module, the CRM/CTI integration effort, and monitoring. Scope those early.
Conclusion
Amazon Connect is the platform, but a successful Amazon Connect project is really the sum of all these products and tools working together — the headset the agent wears, the Terraform that stands the instance up, the pipeline that ships changes safely, the payment module that keeps you out of PCI scope, and the integrations that make any of it useful. Scope them deliberately in discovery and you avoid the classic mid-project scramble of discovering a "missing" product nobody budgeted for.
Next, pair this with the Jira backlog to turn the list into work, and the roles & responsibilities guide to assign owners to each piece.