Skip to main content
A source is one connection Amnify reads. A scope is one thing inside it that gets scanned on its own. You choose the scopes, and the agents only ever look at what you selected.

Selecting scopes

Amnify lists the scopes it can see, all selected. Deselect anything it should leave alone, then save. An unselected scope is never scanned, and produces no findings and no cost. You can change the selection at any time.

Permissions

Amnify requests only the access its work requires. Cloud sources are read only: Amnify reads how resources are configured and has no access to what is inside them. GitHub is the exception, because delivering a fix means writing to the repository, and that write is bounded to a new branch and a pull request. You grant the access on your side and can revoke it at any time. Where the provider allows it the grant is keyless, with no long lived secret to hand over. Where you do supply a credential, it is one you own and can rotate. Each provider is organized into tiers. Tier 1 is the minimum needed to assess a source, and later tiers are optional, widening coverage into the identity layer.

Azure

Read only, via the Amnify enterprise application.

AWS

Read only, via an assumed scan role.

GCP

Read only, via a service account you own.

GitHub

Read, plus bounded write via the Amnify GitHub App.
Removing a source stops all access immediately. Existing findings and history stay readable.
Sources are what Amnify scans. Integrations are the tools your team already works in, such as your ticket tracker.