Selecting scopes
Amnify lists the scopes it can see, all selected. Deselect anything it should leave alone, then save. An unselected scope is never scanned, and produces no findings and no cost. You can change the selection at any time.Permissions
Amnify requests only the access its work requires. Cloud sources are read only: Amnify reads how resources are configured and has no access to what is inside them. GitHub is the exception, because delivering a fix means writing to the repository, and that write is bounded to a new branch and a pull request. You grant the access on your side and can revoke it at any time. Where the provider allows it the grant is keyless, with no long lived secret to hand over. Where you do supply a credential, it is one you own and can rotate. Each provider is organized into tiers. Tier 1 is the minimum needed to assess a source, and later tiers are optional, widening coverage into the identity layer.Azure
Read only, via the Amnify enterprise application.
AWS
Read only, via an assumed scan role.
GCP
Read only, via a service account you own.
GitHub
Read, plus bounded write via the Amnify GitHub App.
Sources are what Amnify scans. Integrations are the tools your team already works in, such as your ticket tracker.