app.arch0.io/signin
arch0

Sign in to arch0

You're on your way to secure your cloud journey.

Don't have an account? Create workspace

// identity posture

Every permission your cloud grants, turned into a feed you can actually read.

HighGetQueryExecution
acl subresource access
Compliance78%
Pass · 1,204 checks

Integrations

Connect a cloud account to start monitoring.

No Integrations yet

Add an integration to start monitoring identity posture, risk and compliance across your cloud.

GitHub
Amazon Web Services

Risk Analysis

Connect Amazon Web Services to scan your identity posture.

Connect AWS

Step 1 of 2

You'll be asked to enter your Amazon ID and validate it. arch0 uses read-only access to analyze permissions — we never store credentials.

Dashboard

Welcome back, Nithin!
Critical
10
▲ 2 this week
High
45
▲ 6 this week
Medium
10k
— stable
Low / Pass
78%
▼ healthy

Activity Feed

View all →

Compliance

See all →
78%PASS
1,204 checks
Pass · 940 Warn · 188 Fail · 76

Identity posture

Critical 40% High 45% Med 13%

2 identities over-privileged across #athena & #users.

Activity Feed

Cloud actions across your workspace, newest first.
← Activity Feed

Activity Detail

High risk
TT
Tilak Timappa@tilak2 mins ago
GetQueryExecution
Grants permissions to use the acl subresource to set the permissions on an existing bucket. This identity can read and modify access-control lists beyond its assigned role.
#athena#users
Browser US East (N. Virginia) ★ 4.9 · 202 reviews

Why it's flagged

The acl subresource permission allows privilege escalation. It sits outside the identity's baseline role and was used from an interactive Browser session rather than CI.

Recommendation

Auto-fix ready
Scope the policy to s3:GetObject on named buckets and remove PutBucketAcl. Apply to restore posture to Pass.

Compliance

Manage your team members and their account permissions here.
Critical
10
controls failing
High
45
need review
Medium
10k
monitored
Pass rate
78%
▲ 4% vs last scan

Controls

Last scan 2h ago

Integrations

Nithin's Workspace · 2 connected

Connected accounts

Risk distribution: Critical · High · Med · Low
GitHub
2 identities · org/arch0
50% · 20% · 10% · 5%
Healthy
Last Scan: 2h ago
Amazon Web Services
us-east-1 · acct 0000-0000
50% · 20% · 10% · 5%
Scanning…
Click around — nav, View all, feed items, Connect & Validate all work.