










Walk right in
Amphi is a shared space where the community comes together to tackle everyday access challenges side-by-side. Everything here is completely open, ungated, and free for everyone.

Take the floor
Learn from fellow practitioners, trade insights, and ask questions - or step up to share your own ideas and help shape the tools the community relies on.

Clear the friction
Stop wrestling with daily access roadblocks alone. Get instant clarity, eliminate repetitive guesswork, and streamline your workday using proven, community-tested solutions.
One Amphi, every step of the policy lifecycle
IAM Expand
See what your wildcards actually grant.
Paste a single action, a code snippet, Terraform, HTML, or a full policy document, and every action pattern comes back expanded to the actions behind it.
IAM Truth
Read a policy as a truth table.
Demystify your SCPS and RCPs. Understand every combination of conditions, and the allow or deny each one produces. No more guessing which requests a guardrail actually blocks.
IAM Test & Simulate
Evaluate requests before they happen in production.
Test a single policy or run a full simulation to preview the impact before deploying. No account needed.
IAM Shrink
Get under the character limit.
Compress your policy’s action list to fit within AWS character limits without changing any granted permissions.
IAM Convert
Turn JSON into infrastructure.
Hand-translating a policy into HCL is where errors come from. Automatically generate ready-to-use Terraform, CDK, or CloudFormation in one click instead.
Map Effective Cloud Access
with IAM Collect & IAM Lens
Download all policies from your cloud accounts into a single local dataset to query real-world reachability. Ask plain questions like ‘Who can access this bucket?’ and get instant answers from your actual configuration.

Runs wherever you build
Let's talk access
We love solving messy cloud access problems. Book 30 minutes with one of our engineers to work through a stubborn policy or rethink an access architecture.
From the trenches
Practical guides, post-mortems, and hard-earned lessons on real-world cloud security written by practitioners.

Reading other AWS accounts' SQL on Amazon Athena
Act's research team uncovered a cross-tenant security flaw in Amazon Athena that exposed recent SQL queries, Account IDs, and sensitive data from unrelated AWS accounts. By passing Catalog=system via an API parameter, queries bypassed standard validation to read shared logs directly from Trino's runtime table. We reported the issue to AWS, and they resolved it globally in four days with no action required on your end.

Streamlining IAM: The open-source policy management toolkit
Access is the foundation of cloud security, and it is also the thing engineers dread touching. The documentation manages to be both overwhelming and insufficient, the AI models are confidently wrong, and questions that sound trivial turn into afternoons of work.





