Amazon Quick's New AI Features Won't Sneak Up on You Anymore — Say Hello to Deny by Default!
Hey everyone, it's Shii-chan! I found a quiet but important update for admins today!
AWS What's NewWhat was announced?
AWS What's New announced that Amazon Quick's custom permissions now include "deny by default," a governance setting that automatically restricts new AI capabilities before they reach users.
The story so far
Until now, whenever a new AI capability shipped, it was automatically available to every user by default. That left administrators reacting after the fact, checking for problems only once a feature was already out in the wild.
What changes
With deny by default, administrators can restrict an AI capability category within a custom permissions profile and assign that profile to users, roles, or the entire account. Users covered by that profile will then have newly launched AI capabilities denied by default — administrators explicitly allow each one only when it's ready.
One thing worth noting: restricting a category also restricts existing capabilities within it, and the restriction only applies to the specific profile you configure.
Dive Deep
You can configure this from the "Manage account" section in Amazon Quick or via the AWS CLI. Deny by default is available in every AWS Region where Amazon Quick is available. For setup details, AWS has documentation on "Custom permissions deny by default."
Wrap-up
- Amazon Quick's custom permissions now support "deny by default"
- Previously, new AI capabilities were automatically open to all users on release
- Admins can now restrict by category and explicitly allow each capability when ready
- Configurable via Manage account or the AWS CLI, available in all regions
- A solid update for admins who want tighter governance over AI capabilities in their org!